Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-31249 PoC — 多款Chiyu产品注入漏洞

Source
Associated Vulnerability
Title:多款Chiyu产品注入漏洞 (CVE-2021-31249)
Description:Chiyu CHIYU BF-430等都是中国台湾七友科技(Chiyu)公司的一款为门禁、考勤系统等设备提供通讯的联网服务器。 CHIYU Technology Inc 的 BF-430、BF-431 和 BF-450M TCP/IP 转换器设备上存在安全漏洞,该漏洞源于缺乏对多个CGI组件上可用的参数重定向=的验证。
Description
CHIYU TCP/IP Converter BF-430, BF-431, and BF-450 are susceptible to carriage return line feed injection. The redirect= parameter, available on multiple CGI components, is not properly validated, thus enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
File Snapshot

id: CVE-2021-31249 info: name: CHIYU TCP/IP Converter - Carriage Return Line Feed Injection aut ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.