D-Link DNS-325 ShareCenter <...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## Table of contents * 00 - Introduction * 00.1 Background * 01 - Unrestricted File Upload * 01.1 - Vulnerable code analysis * 01.2 - Remote exploitation * 02 - Command Injection * 02.1 - Vulnerable code analysis * 02.2 - Remote exploitation * 03 - Credit * 04 - Proof of concept * 05 - Solution * 06 - Contact information ### 00 - Introduction The purpose of this article is to detail the research that I have recently completed regarding the D-Link DNS 325 ShareCenter. #### 00.1 - Background D-Link Share Center DNS-325 2-Bay Network Storage Enclosure is an easy to use solution for accessing, sharing and backing up your important data. ### 01 - Unrestricted file upload The DNS-325 is vulnerable to the same file upload issue as the DNS-320L. The vulnerable code can be found within the following file: `/usr/local/modules/web/pages/jquery/uploader/multi_uploadify.php` The root of the problem here is due to the misuse and misunderstanding of the PHP gethostbyaddr() function used within...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息