taocms icon indicating copy to clipboard operation
taocms copied to clipboard

There is a Arbitrary file download attack at " File Management column"(administrator authority)

Open 7wkajk opened this issue 3 years ago • 0 comments

First, we enter the background and use the administrator admin we created:

image-20211210101406045

Let's click "file management" on the left:

image-20211210102337699

Then use Burp Suite and click Download to grab the request package

image-20211210101704321

image-20211210101728293

Changing the “path” parameter

image-20211210101826206

7wkajk avatar Dec 10 '21 02:12 7wkajk