# 泛微OA sysinterface/codeEdit.jsp 页面任意文件上传 WooYun-2015-0155705

### 漏洞描述 <a href="#lou-dong-miao-shu" id="lou-dong-miao-shu"></a>

泛微OA sysinterface/codeEdit.jsp 页面任意文件上传导致可以上传恶意文件

### 漏洞描述 <a href="#lou-dong-miao-shu" id="lou-dong-miao-shu"></a>

&#x20;Note

较老版本，目前无准确版本

### 漏洞复现 <a href="#lou-dong-fu-xian" id="lou-dong-fu-xian"></a>

`filename=******5308.java&filetype=javafilename为文件名称 为空时会自动创建一个`

```
String fileid = "Ewv";<br>
    String readonly = "";<br>
    boolean isCreate = false;<br>
    if(StringHelper.isEmpty(fileName)) {<br>
     Date ndate = new Date();<br>
     SimpleDateFormat sf = new SimpleDateFormat("yyyyMMddHHmmss");<br>
     String datetime = sf.format(ndate);<br>
     fileid = fileid + datetime;<br>
     fileName= fileid + "." + filetype;<br>
     isCreate = true;<br>
    } else {<br>
        int pointIndex = fileName.indexOf(".");<br>
        if(pointIndex > -1) {<br>
            fileid = fileName.substring(0,pointIndex);<br>
        }}
```

![](https://4279400230-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgxNkYa2vR6HNnHdkjg%2F-Mhm0EXDsKiuDpPeruVH%2F-Mhm2OIFsTs6VIas6MSE%2Fimage.png?alt=media\&token=0ad9094a-c95e-4a53-bdae-6571a53acdd3)

![](https://4279400230-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgxNkYa2vR6HNnHdkjg%2F-Mhm0EXDsKiuDpPeruVH%2F-Mhm2QwCrNo8AV4EC7U_%2Fimage.png?alt=media\&token=5fd88af2-0708-4fb5-8b13-a0ea48c4e78e)

![](https://4279400230-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgxNkYa2vR6HNnHdkjg%2F-Mhm0EXDsKiuDpPeruVH%2F-Mhm2T5PH1jLvwJ8tB5-%2Fimage.png?alt=media\&token=fadffbc9-4c56-4067-b165-d10628614bac)

![](https://4279400230-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgxNkYa2vR6HNnHdkjg%2F-Mhm0EXDsKiuDpPeruVH%2F-Mhm2U_WeB-GP2nzdegp%2Fimage.png?alt=media\&token=77548db2-c12a-47a2-8a9f-39eac0d79788)

![](https://4279400230-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgxNkYa2vR6HNnHdkjg%2F-Mhm0EXDsKiuDpPeruVH%2F-Mhm2XihszguX8kpTzkD%2Fimage.png?alt=media\&token=fe8ce31c-73e8-401b-a6c5-a79d5e080d32)

### 参考文章 <a href="#can-kao-wen-zhang" id="can-kao-wen-zhang"></a>

[泛微OA未授权可导致GetShell](https://www.uedbox.com/post/15730/)
