Description
天锐绿盾审批系统的/trwfe/file/downFileByconfirm.do接口存在文件读取漏洞,攻击者可通过构造包含绝对路径的dstPath参数,发送POST请求读取服务器上的敏感文件,如系统配置文件和凭证信息。
天锐绿盾审批系统的/trwfe/file/downFileByconfirm.do接口存在文件读取漏洞,攻击者可通过构造包含绝对路径的dstPath参数,发送POST请求读取服务器上的敏感文件,如系统配置文件和凭证信息。
None yet. Search at https://trap.biu.life/?ref=rss