目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-42671 PoC — Engineers Online Portal 访问控制错误漏洞

来源
关联漏洞
标题: Engineers Online Portal 访问控制错误漏洞 (CVE-2021-42671)
Description:Engineers Online Portal是开源的一个在线门户。是使用PHP、MySQL 数据库、HTML、CSS、Javascript、jQuery、Ajax、Bootstrap 和一些其他库开发的。 Engineers Online Portal 存在访问控制错误漏洞,该漏洞源于PHP中Sourcecodester Engineers Online Portal中存在一个错误的访问控制漏洞。攻击者可利用该漏洞绕过访问控制,在不需要认证或授权的情况下访问上传到web服务器的所有文件。
Description
CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system. 
介绍
# CVE-2021-42671
CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system. 

# Technical description:
A broken access control vulnerability exists in the Engineers Online Portal. An attacker can leverage this vulnerability in order to bypass access controls and get his hands on all the files uploaded to the web server without the need of authentication or authorization. 

Vulnerable domain - http://localhost/nia_munoz_monitoring_system/admin/uploads/

# Proof of concept (Poc) -
Navigate to http://localhost/nia_munoz_monitoring_system/admin/uploads/ in order to bypass the access control of the target web server. 
As a result you can reach sensetive information stored on the web server uploads folder. 

![CVE-2021-42671](https://user-images.githubusercontent.com/93016131/140196897-9f334ed2-a477-4b5e-a806-57a11d17a615.gif)

# References - 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42671

https://nvd.nist.gov/vuln/detail/CVE-2021-42671

# Discovered by - 
Alon Leviev(0xDeku), 22 October, 2021. 
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →