Lvmeng RSAS security system full edition kill permission administrator bypass vulnerability, including the latest RSAS V5.0.13.2
Rumeng RSAS security system full edition kill Permission Bypass Vulnerability, including the latest RSAS V5.0.13.2
RSAS default Auditor
Account: reporter, auditor
The password is nsfocus.
After logging on to a normal account
View the latest V5.0.13.2 version.
Then, modify the auditor password, capture the packet, and change the auditor in the auditor and post data in the referer to admin, that is, the administrator account. The data packets after the modification are as follows:
After the data is submitted, the system directly returns to the password modification page of our super administrator, who uses logical errors to directly obtain the super permission,
Here, we can directly change the admin password and then submit it:
Super Administrator Login
Solution:
Self-repair.