黑客、渗透测试和网络安全工具,武装您的安全武器库!
针对 CVE-2025-34030 sar2html 'plot' 参数的 RCE PoC
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
CVSS: 10.0 严重 漏洞类型: OS 命令注入 编程语言: PHP 利用代码: Python
参考资料:
sar2html 版本 <= 3.2.1 中存在一个未经身份验证的 OS 命令注入漏洞,通过 index.php 中的 plot 参数触发(index.php?plot=; <command>)。漏洞执行后的输出会显示在应用程序界面中,“select # host” 包含命令输出。
index.php?plot=; <command>