This strike exploits a directory traversal vulnerability in the Yonyou ERP-NC system. Attackers could obtain sensitive file information by sending a HTTP requests to /NCFindWeb with a filename parameter which value is null. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None