Awesome-POC/Web应用漏洞/极通EWEBS testweb.php 敏感信息泄露漏洞.md
2022-12-05 11:09:28 +08:00

33 lines
389 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 极通EWEBS testweb.php 敏感信息泄露漏洞
## 漏洞描述
极通EWEBS testweb.php 存在敏感信息泄露其中含有配置文件信息以及phpinfo信息
## 漏洞影响
```
极通EWEBS
```
## FOFA
```
app="新软科技-极通EWEBS"
```
## 漏洞复现
登录页面如下
![](./images/202202101938494.png)
访问 testweb.php
![](./images/202202101939393.png)