Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

There is a Arbitrary file download attack at " File Management column"(administrator authority) #10

Open
7wkajk opened this issue Dec 10, 2021 · 0 comments

Comments

@7wkajk
Copy link

7wkajk commented Dec 10, 2021

First, we enter the background and use the administrator admin we created:

image-20211210101406045

Let's click "file management" on the left:

image-20211210102337699

Then use Burp Suite and click Download to grab the request package

image-20211210101704321

image-20211210101728293

Changing the “path” parameter

image-20211210101826206

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant