Ruijie_EG_Easy_Gateway_DOWNLOAD_PHP_Arbitrary_File_Reading_Vulnerability

锐捷EG易网关DOWNLOAD.PHP任意文件读取漏洞

Attention

I have developed a tool for local testing and POC development, which is for technical learning reference only. Please do not use it for illegal purposes. Any direct or indirect consequences and losses caused by individuals or organizations using the information provided in this article are the responsibility of the user themselves and have nothing to do with the author!!!

1697433220057

Description

Ruijie Network is a brand of data communication solutions. Ruijie Network adheres to the path of independent research and development, and takes a unique development path in the fiercely competitive network equipment market with "scenario innovation". Since its establishment, Ruijie Network has established its mission to "promote the development of network technology, keep up with the wave of network applications, integrate technology and applications, and promote social progress

installation

pip install -r requirements.txt

Tools Usage

python 锐捷EG易网关DOWNLOAD.PHP任意文件读取漏洞.py  -h
usage: 锐捷EG易网关DOWNLOAD.PHP任意文件读取漏洞.py [-h] (-u URL | -f FILE) [--random-agent RANDOM_AGENT] [--time-out TIME_OUT]
                                      [-d DELAY] [-t THREAD] [--proxy PROXY]

Ruijie EG Easy Gateway DOWNLOAD PHP Arbitrary File Reading Vulnerability

optional arguments:
  -h, --help            show this help message and exit
  -u URL, --url URL     Enter target object
  -f FILE, --file FILE  Input target object file
  --random-agent RANDOM_AGENT
                        Using random user agents
  --time-out TIME_OUT   Set the HTTP access timeout range (setting range from 0 to 5)
  -d DELAY, --delay DELAY
                        Set multi threaded access latency (setting range from 0 to 5)
  -t THREAD, --thread THREAD
                        Set the number of program threads (setting range from 1 to 50)
  --proxy PROXY         Set up HTTP proxy