黑客、渗透测试和网络安全工具,武装您的安全武器库!
Gin v1.7.0 (CVE-2023-29401) 的演示消费者 — Context.FileAttachment 使用用户输入。endorctl scan target.
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
演示消费者固定使用 github.com/gin-gonic/gin v1.7.0(存在 CVE-2023-29401 漏洞)。/download/:filename 处理器直接将用户输入传递给 Context.FileAttachment——这是 Endor 标记为可利用的漏洞利用条件模式。
github.com/gin-gonic/gin v1.7.0
/download/:filename
Context.FileAttachment