关键信息总结 漏洞名称: ASTPP VoIP 4.0.1 - Remote Code Execution EDB-ID: 47889 CVE: N/A 作者: Fabien AUNAY 类型: Remote 平台: Linux 发布日期: 2020-01-08 受影响的应用: ASTPP VoIP 4.0.1 (vendor default setup script) 测试环境: Debian 9 - CentOS 7 漏洞详情 1. Objective 1: html code in SIP Caller Number - POC: 2. Objective 2: XSS injection in SIP Caller Name - POC: 3. Objective 3: XSS document.cookie evasion - POC: 4. Objective 4: XSS document.cookie grabber - POC: 5. Objective 5: Plugin command injection - POC: 6. Objective 6: Reverse shell - POC: 7. Objective 7: Root the system - POC: Exploit cron - Command: 8. Objective 8: Looting - POC: The file contains all information to explore the database.