xxsmile123 / youdata_Vulnerabilities

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

youdata_Vulnerabilities

Two vulnerabilities exist in version 7.20 of the grafana component of the Netnifty BI product: file reading and default password.

Default password

The default password is:admin/admin

Verification Screenshot

Login page image Prompted to change the password, here proves that the default password of grafana component is the above given: admin/admin.Click the skip button here to skip the default password change image Successful login image

File Read

This is magically modified from the payload of grafana's file reading vulnerability (CVE-2021-43798).

payload

/monitor/public/plugins/text/#/../../../../../../../../../../etc/passwd

Verification Screenshot

image

About