Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-34805 PoC — Land Software Faust Iserver 路径遍历漏洞

Source
Associated Vulnerability
Title:Land Software Faust Iserver 路径遍历漏洞 (CVE-2021-34805)
Description:Land Software Faust Iserver是德国Land Software公司的用于将 Faust、Faust Entry 和 Lidos 数据库带到内联网和互联网上。 Land Software FAUST iServer 9.0.017.017.1- 9.0.018.018.4版本存在路径遍历漏洞,该漏洞源于软件缺少对于本地包含的限制,导致本地文件包含漏洞。
Description
FAUST iServer before 9.0.019.019.7 is susceptible to local file inclusion because for each URL request it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
File Snapshot

id: CVE-2021-34805 info: name: FAUST iServer 9.0.018.018.4 - Local File Inclusion author: 0x_Ak ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.