The Sangfor Next-Gen Application... CVE-2023-30805

- AV AC AU C I A
发布: 2023-10-10
修订: 2023-10-13

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息