H3C CVM 是 H3C CAS 云计算平台中的云虚拟化管理组件,其 端点存在一个未授权任意文件上传漏洞。该漏洞允许远程攻击者通过操控用户提供的 token 参数,在不限制路径遍历和文件类型检查的情况下,写入任意文件。攻击者可利用 token 参数中的路径遍历缺陷,将恶意的 JSP 文件上传至可通过 Web 访问的目录,随后通过请求该文件,以 Web 服务器用户的身份实现远程代码执行。该漏洞的利用迹象最初于 2023 年 10 月 14 日被 Shadowserver 基金会发现。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet