Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-48710 — CVE-2026-48710漏洞验证代码 | Kitploit
أدوات/GitHubGitHub/cuteecat/cve-2026-48710
Authentication & AuthorizationVulnerability AnalysisWeb Application ExploitationWeb Security
GitHubcuteecat/cve-2026-48710

CVE-2026-48710

CVE-2026-48710漏洞验证代码

عرض المستودع
منذ 9 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2026-48710

المبدأ:

Starlette هو إطار عمل Python ASGI مفتوح المصدر وخفيف الوزن. ينبع من أن إطار Starlette، عند معالجة بنية بيانات الـ url، يثق في قيمة host التي يرسلها العميل ويضمّنها مباشرة في متغير الـ url للاستخدام لاحقًا في التحقق من الصلاحيات.

يُعالَج الـ url الأصلي في uvicorn\protocols\http\httptools_impl.py:

root@kitploit:~
def on_message_begin(self) -> None:
    self.url = b""
    self.expect_100_continue = False
    self.headers = []
    self.scope = { 
        "type": "http",
        "asgi": {"version": self.asgi_version, "spec_version": "2.3"},
        "http_version": "1.1",
        "server": self.server,
        "client": self.client,
        "scheme": self.scheme,  
        "root_path": self.root_path,
        "headers": self.headers,
        "state": self.app_state.copy(),
    }

# Parser callbacks
def on_url(self, url: bytes) -> None:
    self.url += url #self.url设置为原始url

def on_header(self, name: bytes, value: bytes) -> None:
    name = name.lower()
    if name == b"expect" and value.lower() == b"100-continue":
        self.expect_100_continue = True
    self.headers.append((name, value))

def on_headers_complete(self) -> None:
    http_version = self.parser.get_http_version()
    method = self.parser.get_method()
    self.scope["method"] = method.decode("ascii")
    if http_version != "1.1":
        self.scope["http_version"] = http_version
    if self.parser.should_upgrade() and self._should_upgrade():
        return
    parsed_url = httptools.parse_url(self.url)#使用httptools拆分原始url
    raw_path = parsed_url.path  #raw_path设置为原始url拆分出的path(访问的path)
    path = raw_path.decode("ascii")  #path设置为使用ascii解码以后的原始path值
    if "%" in path:  #处理url解码以后的中文从重编码
        path = urllib.parse.unquote(path)
    full_path = self.root_path + path
    full_raw_path = self.root_path.encode("ascii") + raw_path
    self.scope["path"] = full_path
    self.scope["raw_path"] = full_raw_path
    self.scope["query_string"] = parsed_url.query or b""

(تعليقات كتبتها يدويًا)

هذا الكود موجود داخل class URL: (داخل الـ method).

الكود: \starlette\datastructures.py

host_header = None for key, value in scope["headers"]: if key == b"host": host_header = value.decode("latin-1") break if host_header is not None: url = f"{scheme}://{host_header}{path}" #基于用户传入的请求头二次定义url

في starlette\routing.py:

root@kitploit:~
    route_path = get_route_path(scope)
    if scope["type"] == "http" and self.redirect_slashes and route_path != "/":
        redirect_scope = dict(scope)
        if route_path.endswith("/"):
            redirect_scope["path"] = redirect_scope["path"].rstrip("/")
        else:
            redirect_scope["path"] = redirect_scope["path"] + "/"

        for route in self.routes:
            match, child_scope = route.matches(redirect_scope)
            if match != Match.NONE:
                redirect_url = URL(scope=redirect_scope)   #调用URL方法
                response = RedirectResponse(url=str(redirect_url))
                await response(scope, receive, send)
                return

يؤدي ذلك إلى أن يرسل العميل طلبًا مشوّهًا يحمل ترويسة host إلى نقطة طرفية تتطلب التحقق من الصلاحيات، فعند طبقة التوجيه يُعاد تعريف الـ url إلى نقطة طرفية لا تتطلب تحققًا. مثال: في http://127.0.0.1:9999/admin يحتوي هذا الـ url على نقطة طرفية admin تتطلب التحقق من الصلاحيات.

إرسال حزمة: url = http://127.0.0.1:9999/admin header{ host = 123? }

عندها يُعاد تعريف الـ url إلى http://123?/admin ويُستخدم عندها دالة urlsplit لتحليل الـ url تكون النتيجة SplitResult(scheme='http', netloc='123', path='', query='/admin', fragment='') ولأن path=''، يعتبر التحقق اللاحق أن المستخدم يزور جذر الموقع، فيُسمح له مباشرة، بينما يُرجع فعليًا محتوى دليل admin.

تنزيل الأداة