Skip to content

Latest commit

 

History

History
23 lines (12 loc) · 1.05 KB

information_disclosure.md

File metadata and controls

23 lines (12 loc) · 1.05 KB

An unauthorized vulnerability exists in the Smart S85F management platform

1.Vulnerability description

Beijing Baichao Network Technology Co., LTD. (hereinafter referred to as Baichao Network) is a high-tech enterprise committed to building the next generation of secure Internet.

An unauthorized vulnerability exists in the database management of the Smart S85F management platform. Attackers can use the vulnerability to gain server permissions or affect services in the system.

2.Vulnerability url:/sysmanage/licence.php

3.Vulnerability recurrence

Search in fofa: app="Smart Management Platform "&&body ="S85F"

WPS图片(1)

See the login page.

WPS图片(2)

Construct the url: https://ip:port/sysmanage/licence.php, unauthorized access, success can be unauthorized operation

WPS图片(3)