Add CNVD-2020-30193

This commit is contained in:
xiaoheihei1107 2021-08-18 10:58:15 +08:00 committed by GitHub
parent 5a374e5976
commit b15aee6e26
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,11 @@
# AVCON-6 download.action File Read (CNVD-2020-30193)
The AVCON-6 system management platform download.action and org_execl_download.action have arbitrary file download vulnerabilities. Attackers can download arbitrary files on the server through the vulnerabilities.
FOFA **query rule**: [app="AVCON-6"](https://fofa.so/result?qbase64=YXBwPSJBVkNPTi02Ig%3D%3D)
# Demo
![AVCON_6_download_action_File_Read_CNVD_2020_30193](AVCON_6_download_action_File_Read_CNVD_2020_30193.gif)