We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
存在任意文件读取漏洞
No response
v1.10.0
Docker
The text was updated successfully, but these errors were encountered:
看了下, 是 soar 这边既可接受 sql 语句又可接受文件路径导致的, 这块如果说过滤请求, 不是特别好判断是不是真正的 SQL 语句, 我这边做了一个针对性修复, 针对你说的读取文件的bug 做了修复
Sorry, something went wrong.
Successfully merging a pull request may close this issue.
重现步骤
预期外的结果
存在任意文件读取漏洞
日志文本
No response
版本
v1.10.0
部署方式
Docker
是否还有其他可以辅助定位问题的信息?比如数据库版本等
No response
The text was updated successfully, but these errors were encountered: