Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-9632 PoC — ESAFENET CDG 安全特征问题漏洞

Source
Associated Vulnerability
Title:ESAFENET CDG 安全特征问题漏洞 (CVE-2019-9632)
Description:ESAFENET CDG是一套文档安全管理系统。 ESAFENET CDG V3和V5版本中存在任意文件下载漏洞,该漏洞源于程序没有正确地处理‘InstallationPack’参数。攻击者可借助download.jsp文件中的‘fileName’参数利用该漏洞无需登录便可下载任意文件。
Description
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
File Snapshot

id: CVE-2019-9632 info: name: ESAFENET CDG - Arbitrary File Download author: pdteam severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.