杭州九麒科技大蚂蚁即时通讯 /Api/Update/down.html 文件读取漏洞

Description

杭州九麒科技 BigAnt-Admin /Api/Update/down.html 接口存在文件读取漏洞,未经身份攻击者可通过该漏洞在服务器端任意文件读取。攻击者可以利用该漏洞读取设备上的任意文件内容,导致敏感信息泄露。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References