Sunlogin Sunflower Simplified (aka... CVE-2022-48323

- AV AC AU C I A
发布: 2023-02-13
修订: 2024-11-21

Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息