漏洞描述 红帆OA 是一款为医院提供oA功能,完成信息发布、流程审批、公文管理、日程管理、工作安排、文件传递、在线沟通等行政办公业务。红帆OA iorepsavexml.aspx文件存在任意文件上传漏洞,攻击者可上传恶意木马获取服务器权限。
相关漏洞推荐 红帆OA /ioffice/prg/Mobile/Base/MobileBind.aspx SQL 注入漏洞 红帆ioffice HbcaUserLogin.aspx SQL注入漏洞 红帆ioffice mrClearPwd.aspx SQL注入漏洞 红帆ioffice PgcaUserLogin.aspx SQL注入漏洞 POC hongfan-iodesktopdata-sqli: 红帆iOffice ioDesktopData.asmx接口SQL注入 POC hongfan-ioffice-iofiledown-fileread: 红帆 iOffice ioFileDown 任意文件读取漏洞 POC hongfan-oa-iorepsavexml-file-upload: 红帆OA iorepsavexml.aspx 任意文件上传 POC ioffice-oa-iofileexport-read-file: 红帆OA ioFileExport.aspx 任意文件读取漏洞 POC ioffice-oa-udfmr-asmx-sql-inject: 红帆OA udfmr.asmx SQL注入漏洞 POC hongfan-ioffice-lfi: Hongfan OA ioFileExport.aspx - Arbitrary File Read POC hongfan-ioffice-rce: Hongfan OA ioAssistance.asmx - Remote Code Execution POC hongfan-ioffice-sqli: Hongfan OA udfmr.asmx - SQL injection POC 红帆 ioffice /iOffice/Identity/NetCAUserLogin.aspx SQL 注入漏洞