当前位置:网站首页>Torth file read vulnerability (cnvd-2020-27769)
Torth file read vulnerability (cnvd-2020-27769)
2022-07-26 06:37:00 【Thousand miles:)】
Vulnerability profile
Torth Chinese retrieval system TRSWAS5.0 web/tree Interface treefile There is a file reading vulnerability in the parameter , Can read the database configuration file 、 Account password and other information , It leads to the disclosure of configuration file information and threatens the security of the website .
The recurrence process
http://xx.com/was5/web/tree?treefile=/WEB-INF/classes/com/trs/was/resource/wasconfig.properties
If the vulnerability exists , The contents of the file are displayed
Means of repair
At present, the official has fixed this vulnerability in the new version , You can download from the official to upgrade the corresponding components or use the files in the attachment trswas.jar Replace directory D:\TRS\TRSWAS5.0\Tomcat\webapps\was5\WEB-INF\lib The files under the
Reference resources
https://blog.csdn.net/weixin_43650289/article/details/109072674
边栏推荐
- Database and the future of open source
- Alibaba cloud OSS binding custom domain name
- 信号处理系统综合设计-求解器函数的设计(连续和离散时间系统)
- Go的map字典及约束
- C语言进阶——可存档通讯录(文件)
- 数据库中varchar和Nvarchar区别与联系
- Servlet cannot directly obtain JSON format data in request request
- What is KVM? What is KVM virtual machine?
- Yolov6: the fast and accurate target detection framework is open source
- "Harmonyos" explore harmonyos applications
猜你喜欢

Map collection inheritance structure

力扣——3. 无重复字符的最长子串

『牛客|每日一题』逆波兰表达式

Multi target detection
![[pytorch] CNN practice - flower species identification](/img/af/81e2735ba385ba3d851e61a5fe2bef.png)
[pytorch] CNN practice - flower species identification

【无标题】

【pytorch】微调技术

机械制造企业如何借助ERP系统,做好生产管理?

Input the records of 5 students (each record includes student number and grade), form a record array, and then output them in order of grade from high to low The sorting method adopts selective sortin

原生高性能抓包工具Proxyman,送给爱学习的你
随机推荐
Do you think you are a reliable test / development programmer? "Back to the pot"? Surface and reality
【图像去噪】基于双立方插值和稀疏表示实现图像去噪matlab源码
BPG笔记(四)
Yolov6: the fast and accurate target detection framework is open source
【Day03_0420】C语言选择题
Address resolution ARP Protocol
[day02_0419] C language multiple choice questions
Code runner for vs code, with more than 40million downloads! Support more than 50 languages
Alibaba cloud OSS binding custom domain name
PG Vacuum 杂谈之 auto vacuum
JVM class loading and GC garbage collection mechanism
『牛客|每日一题』点击消除
【Day_02 0419】排序子序列
Differences and relations between varchar and nvarchar in database
Should we test the Dao layer?
Problems related to the use of ucharts (components) in uniapp
Why use the static keyword when defining methods
[day_050422] statistical palindrome
TPS Motion(CVPR2022)视频生成论文解读
[pytorch] fine tuning technology
