jx-sec / jxwaf

JXWAF是一款开源web应用防火墙
https://www.jxwaf.com/
GNU General Public License v2.0
1.11k stars 259 forks source link

目录穿越漏洞漏报 #24

Closed plane636 closed 4 years ago

plane636 commented 4 years ago

awvs测试的,payload:/index.php?PathToDocument=documentation/how-to-access-Mutillidae-over-Virtual-Box-network.php&page=/etc/passwd

jx-sec commented 4 years ago

mark,这种偏向后门型的回通过虚拟补丁处理