NVRMini2ÉãÏñÍ·ÑÏÖØÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-09-21Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-1150£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
NUUO NVRMini2 3.8.0¼°ÒÔϰ汾
Îó²î¸ÅÊö
CVE-2018-1149£ºÎ´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¿ÍÕ»»º³åÇøÒç³ö
CVE-2018-1150£ººóÃÅ
NVRMini2µÄ½á¹¹¼òͼÈçÏÂ
Îó²îÑéÖ¤
NVRMini2ϵͳ¶ÔÍâ̻¶ÁËÒ»¸öHTTP»á¼û½Ó¿Úhttp://<target>/cgi-bin/cgi_system£¬£¬£¬£¬£¬Í¨¹ýÕâ¸ö½Ó¿Ú£¬£¬£¬£¬£¬¾ßÓÐȨÏÞµÄÓû§¿ÉÒÔ»á¼ûµ½ÖÕ¶Ë×°±¸¡£¡£¡£cgi_systemÎļþÖеĹ¦Ð§Ö»ÓÐÊÚȨÓû§¿ÉÒÔ»á¼û£¬£¬£¬£¬£¬ÈÏÖ¤µÄÒªÁìΪ½ÏÁ¿Óû§»á¼ûÊý¾ÝCookie×Ö¶ÎÖеÄPHPSESSIDÖµºÍ´æ´¢/tmpĿ¼ÖеÄsessionÎļþÃû£¬£¬£¬£¬£¬¹¹½¨sessionÎļþÃûµÄ´úÂëÈçÏ£º
²âÊÔ´úÂëÈçÏ£º
²âÊÔ´úÂë»áµ¼ÖÂNVRϵͳ»á±¬·¢Íß½âÕ÷Ï󣬣¬£¬£¬£¬¾ÓÉÉîÈëÆÊÎö£¬£¬£¬£¬£¬Ò²¿ÉÒÔÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬¹¥»÷Õß²»µ«Äܹ»¿ØÖÆNVR£¬£¬£¬£¬£¬»¹¿ÉÒÔ»á¼ûºÍÐÞ¸ÄNVRÖÐËùÓеÄÓû§Æ¾Ö¤Êý¾Ý£¬£¬£¬£¬£¬Ó°ÏìÑÏÖØ¡£¡£¡£
NVRMini2µÄPHP´úÂëÖг£¼ûµÄϰ¹ßΪ£º
¼ì²éÄ¿½ñPHP»á»°ÊÇ·ñÓÐÓᣡ£¡£
ÑéÖ¤»á»°ÊÇ·ñ¾ßÓÐÕýÔÚ»á¼ûµÄÒ³ÃæµÄÊʵ±È¨ÏÞ£¨¼´admin£¬£¬£¬£¬£¬poweruser£¬£¬£¬£¬£¬user£¬£¬£¬£¬£¬root£¬£¬£¬£¬£¬guest£©¡£¡£¡£
¿ÉÊÇ£¬£¬£¬£¬£¬check_session_is_valid£¨£©º¯ÊýÖÐÈ´±£´æºóÃŵĴúÂ룬£¬£¬£¬£¬º¯ÊýÈçÏ£º
¹¥»÷ÑÝʾÊÓÆµÈçÏ£º
http://www.iqiyi.com/w_19s2b6hn11.htmlÐÞ¸´½¨Òé
¹Ù·½ÔÝʱûÓÐÏà¹ØµÄ¼Æ»®£¬£¬£¬£¬£¬½¨Òé°ü¹Ü×°±¸²»Ì»Â¶ÔÚ»¥ÁªÍøÉÏ£¬£¬£¬£¬£¬²¢ÔÚ·À»ðǽװ±¸ÉϼÓÈë¶ÔÉãÏñÍ·HTTPЧÀ͵Ļá¼û¿ØÖÆÕ½ÂÔ¡£¡£¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ