在 Netgate pfSense Plus 26.07 之前版本以及 pfSense CE 2.9.0 之前版本中,Dashboard(index.php)的部件序列数据处理存在本地文件包含(LFI)漏洞,允许经过身份验证的攻击者执行任意 PHP 代码。攻击者若拥有修改 Dashboard 设置以及向 pfSense 防火墙系统写入任意文件的权限(例如写入 /tmp/test.widget.php),可通过提交包含路径遍历载荷的构造化部件序列值(例如 ../../../../../../../../../../.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Netgate | pfSense CE | < 2.9.0 |
affected |
| Netgate | pfSense Plus | < 26.07 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Netgate | pfSense Plus | 0 ~ 26.07 | - |
|
| Netgate | pfSense CE | 0 ~ 2.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet