# N/A
## 漏洞概述
ES File Explorer File Manager 应用通过59777端口上的TCP请求,在本地Wi-Fi网络中允许远程攻击者读取任意文件或执行应用程序。该端口在ES应用启动后保持打开状态,并通过HTTP响应未经身份验证的应用/json数据。
## 影响版本
- 4.1.9.7.4及以下版本
## 漏洞细节
该漏洞通过TCP端口59777上的请求在本地Wi-Fi网络中发起攻击。一旦ES应用被启动过,这个TCP端口将一直保持开放状态。通过HTTP传输未经身份验证的application/json数据,该应用会进行响应。
## 影响
- 远程攻击者可以读取任意文件
- 远程攻击者可以执行应用程序
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | ES File Explorer Open Port Vulnerability - CVE-2019-6447 | https://github.com/fs0c131y/ESFileExplorerOpenPortVuln | POC详情 |
2 | ES File Explorer Open Port Vulnerability - CVE-2019-6447 | https://github.com/SandaRuFdo/ES-File-Explorer-Open-Port-Vulnerability---CVE-2019-6447 | POC详情 |
3 | My exploit for ES Explorer Android App open port vulnerability. | https://github.com/Nehal-Zaman/CVE-2019-6447 | POC详情 |
4 | None | https://github.com/crypticdante/CVE-2019-6447 | POC详情 |
5 | Very basic bash script to exploit the CVE-2019-6447. | https://github.com/julio-cfa/POC-ES-File-Explorer-CVE-2019-6447 | POC详情 |
6 | ES File Explorer v4.1.9.7.4 Open port vulnerability exploit. CVE-2019-6447 | https://github.com/febinrev/CVE-2019-6447-ESfile-explorer-exploit | POC详情 |
7 | None | https://github.com/Kayky-cmd/CVE-2019-6447--. | POC详情 |
8 | This repository is developed to understand CVE-2019-6447 | https://github.com/VinuKalana/CVE-2019-6447-Android-Vulnerability-in-ES-File-Explorer | POC详情 |
9 | The above investigation of the ES file browser security weakness allows us to see the issue in its entirety | https://github.com/Osuni-99/CVE-2019-6447 | POC详情 |
10 | Exploiting Android Vulnerability in ES File Explorer | https://github.com/Chethine/EsFileExplorer-CVE-2019-6447 | POC详情 |
11 | This paper is about manual exploitation of android open port vulnerability found in ES file manager. This open TCP 59777 port allows the attacker to install a backdoor and gather all the user’s data. Further in this paper there will be a proof of concept presented to consolidate the vulnerability. Download the PDF and enjoy !!! Cheers !!! | https://github.com/vino-theva/CVE-2019-6447 | POC详情 |
12 | None | https://github.com/KaviDk/CVE-2019-6447-in-Mobile-Application | POC详情 |
13 | None | https://github.com/H3xL00m/CVE-2019-6447 | POC详情 |
14 | None | https://github.com/n3ov4n1sh/CVE-2019-6447 | POC详情 |
15 | None | https://github.com/c0d3cr4f73r/CVE-2019-6447 | POC详情 |
16 | None | https://github.com/Sp3c73rSh4d0w/CVE-2019-6447 | POC详情 |
17 | year 2 semester 1 Systems and Network Programming Assignment | https://github.com/Cmadhushanka/CVE-2019-6447-Exploitation | POC详情 |
18 | None | https://github.com/0xwh1pl4sh/CVE-2019-6447 | POC详情 |
19 | None | https://github.com/N3rdyN3xus/CVE-2019-6447 | POC详情 |
20 | None | https://github.com/NyxByt3/CVE-2019-6447 | POC详情 |
21 | None | https://github.com/h3xcr4ck3r/CVE-2019-6447 | POC详情 |
22 | None | https://github.com/n3rdh4x0r/CVE-2019-6447 | POC详情 |
23 | None | https://github.com/h3x0v3rl0rd/CVE-2019-6447 | POC详情 |
暂无评论