Arbitrary File Reading Vulnerability in Huaxia Fund's main site
URL: http://www.chinaamc.com: 80/portal/en/second. jsp POST parameters: button = Get % 20 NAVs & categoty_link_nav = xxxxxxxx & column = ROOT> en> Investment % 20 Products> ABF % 20 China % 20 Bond % 20 Index % 20 Fund> Fund % 20 Unit % 20NAV % 20 (Class % 20A) & columnId = 1302845853100 & flg = 1 & fromDate = 01/01/1967 & link_page =/portal/en/second. jsp & minisite_column = ROOT> en> Investment % 20 Products> ABF % 20 China % 20 Bond % 20 Index % 20 Fund> Fund % 20 Unit % 20NAV % 20 (Class % 20A) & minisite_columnId = 1147311052100 & styleFlag = chanpin1a & submited = Y & time = 1 & toDate = 01/01/1967 problem parameter categoty_link_navDNS configuration information
Web. xml Information
Mail Information
You may need to use the dictionary to run files later.
Solution:
Filter special characters