Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-3378 PoC — RZK Fortilogger 代码问题漏洞

Source
Associated Vulnerability
Title:RZK Fortilogger 代码问题漏洞 (CVE-2021-3378)
Description:RZK Fortilogger是土耳其RZK公司的一个可为Windows系统上FortiGate防火墙进行即时状态跟踪,日志记录,搜索/过滤,报告和热点等功能的建站系统。 FortiLogger 4.4.2.2 存在安全漏洞,该漏洞源于受任意文件上传的影响。
Description
FortiLogger 4.4.2.2 is affected by arbitrary file upload issues. Attackers can send a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then Assets/temp/hotspot/img/logohotspot.asp.
File Snapshot

id: CVE-2021-3378 info: name: FortiLogger 4.4.2.2 - Arbitrary File Upload author: dwisiswant0 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.