Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-41291 PoC — Ecoa Bas controller 路径遍历漏洞

Source
Associated Vulnerability
Title:Ecoa Bas controller 路径遍历漏洞 (CVE-2021-41291)
Description:Ecoa Technologies Corp Ecoa Bas controller是中国Ecoa Technologies Corp公司的一个楼宇自动化控制器。 Ecoa Bas controller存在路径遍历漏洞,未经身份验证的攻击者可以远程披露受影响设备上的目录内容。
Description
The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device
File Snapshot

id: CVE-2021-41291 info: name: ECOA Building Automation System - Directory Traversal Content Disc ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.