Description 【漏洞对象】Hanweb 【涉及版本】opr_readfile.jsp filename 【漏洞描述】该程序存在任意文件读取漏洞,由于参数flowcode未过滤导致可读取敏感文件。
Related Vulnerabilities大汉JCMS /design/readxml.jsp 存在任意文件读取大汉Hanweb /jis/down.jsp 路径存在任意文件下载漏洞Hanweb vc任意文件下载hanweb sysid任意文件读取Hanweb selectx_search.jsp spell-SQL注入Hanweb rssfeed.jsp colid-SQL注入Hanweb reg_2.jsp sysid-文件包含漏洞hanweb keyword-SQL注入Hanweb opr_setappraisal.jsp vc_setapprid-SQL注入Hanweb opr_readfile.jsp filename-任意文件读取Hanweb opr_individuation_unit.jsp-任意文件覆盖Hanweb opr_datacall.jsp vc_id-SQL注入Hanweb opr_classajax.jsp classid-SQL注入