You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When accessing the triggerUnitCover Interface with special request, unauthorized attackers can execute any command on the target system. Attacker can inject command in the parameter uuid.
Proof of concept:
The request with file creation and results are as following.
After sending the payload, wait for a period of time (10 seconds by default). Once the scheduled task is executed, you will find that the file is successfully created.
The payload for reverse shell and execution results are as following.
After sending the payload, wait for a period of time (10 seconds by default). Once the scheduled task is executed, you will find that the file is successfully created.
When accessing the triggerUnitCover Interface with special request, unauthorized attackers can execute any command on the target system. Attacker can inject command in the parameter uuid.
Proof of concept:
The request with file creation and results are as following.
After sending the payload, wait for a period of time (10 seconds by default). Once the scheduled task is executed, you will find that the file is successfully created.
The payload for reverse shell and execution results are as following.
After sending the payload, wait for a period of time (10 seconds by default). Once the scheduled task is executed, you will find that the file is successfully created.
The text was updated successfully, but these errors were encountered: