漏洞描述 泛微协同管理应用平台(e-cology)是一套兼具企业信息门户、知识文档管理、工作流程管理、人力资源管理、客户关系管理、项目管理、财务管理、资产管理、供应链管理、数据中心功能的企业大型协同管理平台,并可形成一系列的通用解决方案和行业解决方案。 泛微ecology 9系统存在信息泄露漏洞,攻击者通过构造特殊URL地址,可以读取ecology_dev.zip文件。
相关漏洞推荐 ecology-ebridge-addtaste-sqli: 泛微云桥 taste/addTaste SQL注入 ecology-ifnewscheckoutbycurrentuser-dwr-sqli: 泛微 E-Cology ifnewscheckoutbycurrentuser.dwr SQL 注入 ecology-ktreeuploadaction-upload: 泛微 e-cology 任意文件上传 POC ecology-e-office-mysql-config-leak: 泛微OA E-Office mysql_config.ini 数据库信息泄漏 POC ecology-arbitrary-file-upload: 泛微OA e-cology V9前台任意上传漏洞 POC ecology-e-office-getselectlist-crm-sqli: 泛微e-office系统存在SQL注入漏洞 POC ecology-filedownloadforoutdoc-sqli: 泛微 OA filedownloadforoutdoc - SQL injection POC ecology-mobile-plugin-checkserver-sqli: 泛微 Ecology OA SQL 注入漏洞 POC ecology-ofslogin-aul: 泛微 e-cology 任意用户登录漏洞 POC ecology-v9-sqli: Ecology 9 - SQL Injection POC weaver-ecology9-filedownloadlocation-sqli: Weaver E-cology 9.x FileDownloadLocation SQL Injection POC ecology-oa-file-sqli: E-cology FileDownloadForOutDocSQL - SQL Injection POC ecology-jqueryfiletree-traversal: Weaver E-Cology JqueryFileTree - Directory Traversal