漏洞描述 蓝凌OA是一款针对中小企业的移动化智能办公产品,融合了钉钉数字化能力与蓝凌多年OA产品与服务经验,能全面满足企业日常办公在线、企业文化在线、客户管理在线、人事服务在线、行政务服务在线等需求。蓝凌OA前台存在SQL报错注入,可导致管理员密码泄露,造成攻击者获取管理员权限。
相关漏洞推荐 蓝凌EKP /third/im/kk/webparts/getGzhInfo.jsp 服务器端请求伪造漏洞 蓝凌OA erp_data.jsp存在远程命令执行漏洞 蓝凌OA sysUiExtend.do 存在任意文件上传漏洞 蓝凌OA /sys/ui/sys_ui_component/sysUiComponent.do 命令执行漏洞 POC landray-dataxml-jsp-rce: 蓝凌OA dataxml.jsp 远程命令执行漏洞 POC landray-ekp-sysFormMainDataInsystemWebservice-fileread: Landray EKP sysFormMainDataInsystemWebservice File Read POC landray-oa-datajson-rce: Landray OA Datajson RCE POC landray-oa-kmImeetingBookWebService-fileread: Landray OA kmImeetingBookWebService File Read POC landray-oa-kmImeetingResWebService-fileread: Landray OA kmImeetingResWebService File Read POC landray-oa-loginWebserviceService-fileread: Landray OA loginWebserviceService File Read POC landray-oa-sysNotifyTodoWebService-fileread: Landray OA sysNotifyTodoWebService File Read POC landray-oa-sysNotifyTodoWebServiceEkpj-fileread: Landray OA sysNotifyTodoWebServiceEkpj File Read POC landray-oa-syssearchmain-rce: Landray sysSearchMain.do RCE