Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-41293 PoC — Ecoa Bas controller 路径遍历漏洞

Source
Associated Vulnerability
Title:Ecoa Bas controller 路径遍历漏洞 (CVE-2021-41293)
Description:Ecoa Technologies Corp Ecoa Bas controller是中国Ecoa Technologies Corp公司的一个楼宇自动化控制器。 Ecoa Bas controller存在路径遍历漏洞,未经身份验证的攻击者可以远程泄露受影响设备上的任意文件并泄露敏感和系统信息。
Description
The ECOA BAS controller suffers from an arbitrary file disclosure vulnerability. Using the 'fname' POST parameter in viewlog.jsp, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
File Snapshot

id: CVE-2021-41293 info: name: ECOA Building Automation System - Arbitrary File Retrieval autho ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.