WDMyCloud 2.30.165 CSRF / File...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Released Date: 2018-01-04 Last Modified: 2017-06-11 Company Info: Western Digital Version Info: Vulnerable * MyCloud <= 2.30.165 * MyCloudMirror <= 2.30.165 * My Cloud Gen 2 * My Cloud PR2100 * My Cloud PR4100 * My Cloud EX2 Ultra * My Cloud EX2 * My Cloud EX4 * My Cloud EX2100 * My Cloud EX4100 * My Cloud DL2100 * My Cloud DL4100 Not Vulnerable * MyCloud 04.X Series ### Table of contents 00 - Introduction * 00.1 Background 01 - Unrestricted file upload * 01.1 - Vulnerable code analysis * 01.2 - Remote exploitation 02 - Hard coded backdoor * 02.1 - Vulnerable code analysis * 02.2 - Remote exploitation 03 - Miscellaneous security issues * 03.1 - Cross site request forgery * 03.2 - Command injection * 03.3 - Denial of service * 03.4 - Information disclosure 04 - Reused Code 05 - Credit 06 - Proof of concept 07 - Disclosure timeline 08 - Solution 09 - Contact information 10 - References ### Introduction The purpose of this article is to detail the research that I have completed...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息