RULE(RULE ID:337894)

Rule General Information
Release Date: 2024-04-02
Rule Name: Dahua Smart Park Management poi Interface Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Dahua Smart Park Management is a comprehensive management solution developed by Dahua Technology Co., LTD. The platform is designed to help park managers improve management efficiency, enhance safety, optimize resource utilization, and realize intelligent park operations. There is any file upload vulnerability in the poi path of Dahua Smart Park Management, the attacker can execute code arbitrarily on the server side through the vulnerability, write the backdoor, obtain server permissions, and then control the entire web server.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.