References https://www.exploit-db.com/exploits/48812 https://github.com/zoujingli/ThinkAdmin/issues/244 https://zhuanlan.zhihu.com/p/260828612 https://www.cnblogs.com/r00tuser/p/13719819.html https://github.com/simonlee-hello/CVE-2020-25540 https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/Thinkadmin/ThinkAdmin%20v6%20%E5%88%97%E7%9B%AE%E5%BD%95%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96/ https://www.cnblogs.com/yuzly/p/13689862.html https://cloud.tencent.com/developer/article/1943153 https://github.com/shadow1ng/fscan/issues/122 https://whippet0.github.io/2020/09/27/Thinkadmin%20v6%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2020-25540)/
Related Vulnerabilitiessmartbi-smartbi-bi-readfile: Smartbi smartbi_bi 任意文件读取PoCCVE-2020-25540: ThinkAdmin 6 - Local File InclusionPoCCVE-2024-36857: Jan v0.4.12 'readFileSync' - Path TraversalPoCnsfocus-sas-getfile-readfile: 绿盟 SAS堡垒机 GetFile 任意文件读取漏洞PoCsecworld-secips-3600-debuginfo-readfile: 网神 SecIPS 3600 debug_info_export 任意文件下载科荣AIO /ReadFile 文件读取漏洞科荣 AIO 管理系统 /ReadFile接口 tempFile参数 任意文件读取漏洞大汉JCMS /guestbook/opr_readfile.jsp 存在任意文件读取OfficeWeb-365-Readfile-任意文件读取SIEMENS 摄像头 /readfile.cgi 路径存在敏感信息泄露ThinkAdmin 后台未授权访问ThinkAdminV6 任意文件操作(CVE-2020-25540)