海康威视视频接入网关系统...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

###0x01漏洞简介 海康威视视频接入网关系统采用PHP+SQLite架构,其在以下34处均存在注入漏洞: ``` /userInfo/roleInfo.php /userInfo/userInfo.php /data/fetchRoleTreeJson.php /deviceConfig/configDeviceInfo.php /transformServer/serverConfigInfo.php /cameraConfig/transferInfo.php /data/deviceAndCameraListData.php /data/deviceTypeData.php /data/checkIsExist.php /data/fetchIoInfoData.php /data/saveDeviceType.php /data/saveDecodeServer.php /data/fetchGroup.php /data/login.php /data/transferCamera.php /data/modifyPassword.php /data/fetchDeviceByGroupId.php /data/deleteDeviceInfo.php /data/modifyDeviceInfo.php /data/decodeServerData.php /data/userInfoData.php /data/checkDevice.php /data/deviceListData.php /data/saveUserInfo.php /data/fetchCameraInfo.php /data/fetchDeviceType.php /data/saveGroup.php ``` 远程攻击者可以利用Union方式执行SQL指令,获取敏感信息。 ###0x02漏洞详情 第一处注入:/userInfo/userInfo.php ``` <?php include('../common/connDb.php'); include('roleInfoClass.php'); $dbQuery = new DataBaseQuery(); $isEmpty = empty($_GET['userId']); $userId = "";...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息