From 637865471e35c46bc59a1b206bfa6889119e9643 Mon Sep 17 00:00:00 2001 From: xiaoheihei1107 <62200676+xiaoheihei1107@users.noreply.github.com> Date: Mon, 30 Aug 2021 16:03:21 +0800 Subject: [PATCH] Add Kingsoft V8V9 get_file_content.php File Read --- Kingsoft/get_file_content_php/README.md | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 Kingsoft/get_file_content_php/README.md diff --git a/Kingsoft/get_file_content_php/README.md b/Kingsoft/get_file_content_php/README.md new file mode 100644 index 0000000..879da68 --- /dev/null +++ b/Kingsoft/get_file_content_php/README.md @@ -0,0 +1,9 @@ +# Kingsoft V8 V9 get_file_content.php Arbitrary File Read + +Kingsoft V8, V9 terminal security system has arbitrary file reading vulnerabilities. Attackers can download arbitrary files in the WEB directory through the vulnerabilities. + +FOFA **query rule**: [body="金山安全管理" && title="终端安全系统"](https://fofa.so/result?qbase64=Ym9keT0i6YeR5bGx5a6J5YWo566h55CGIiYmdGl0bGU9Iue7iOerr%2BWuieWFqOezu%2Be7nyI%3D) + +# Demo + +![Kingsoft_V8V9_get_file_content_php_Arbitrary_File_Read](Kingsoft_V8V9_get_file_content_php_Arbitrary_File_Read.gif)