漏洞描述
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.1024sou.comhttps://www.1024sou.com/article/741374.html↗copyfuture.comhttps://copyfuture.com/blogs-details/202202192249158884↗www.cnvd.org.cnhttps://www.cnvd.org.cn/flaw/show/CNVD-2022-10270↗www.cnvd.org.cnhttps://www.cnvd.org.cn/flaw/show/CNVD-2022-03672↗asec.ahnlab.comhttps://asec.ahnlab.com/en/47088/↗