POC详情: aae655224289b6878467d1ca3bab2ae6ecdcdc7a

来源
关联漏洞
标题: Cisco Adaptive Security Appliances Software 路径遍历漏洞 (CVE-2020-3452)
描述:Cisco Adaptive Security Appliances Software(ASA Software)是美国思科(Cisco)公司的一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。 Cisco Adaptive Security Appliances Software和FTD Software中存在路径遍历漏洞,该漏洞源于受影响设备没有正确验证HTTP请求中的URL。远程攻击者可通过将包含目录遍历字符序列的特制HTTP请求发送到受影响的设备利用该漏洞在目标设备上查
描述
CVE-2020-3452 exploit
介绍
# CVE-2020-3452

## TL;DR
This is an exploit for CVE-2020-3452. It's not entirely finished yet. Use it in legal context. If you fuck up it's your problem.

## W00t is dis?
This is a quick'n dirty try to enhance the original PoC of CVE-2020-3452.

At the current stage there is nothing more than a simple py script that does exactly the same as the original.

## Disclaimer
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

## Copyright
The entire code written in Python was written by me (tacticalDevC) but all credits and props go to the original author [0xmmnbassel](https://www.exploit-db.com/?author=10673) and the both discoverers [Ahmed Aboul-Ela](https://twitter.com/aboul3la) and [Abood Nour](https://twitter.com/AboodNour)
文件快照

[4.0K] /data/pocs/aae655224289b6878467d1ca3bab2ae6ecdcdc7a ├── [1.6K] cisco-asa-CVE-2020-3452.py ├── [1.0K] LICENSE └── [1.1K] README.md 0 directories, 3 files
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。