漏洞描述 远程代码执行漏洞是指攻击者通过某些漏洞在服务器上执行任意代码,这通常是由于应用程序对外部输入的验证不足或处理不当造成的。攻击者可以利用这个漏洞上传恶意代码或直接通过HTTP请求发送恶意代码,从而控制服务器,进行包括数据窃取、网站篡改、服务器资源滥用等在内的多种恶意行为。
相关漏洞推荐 POC tongda-action-uploadfile: Tongda OA v2017 action_upload - Arbitrary File Upload POC tongda-api-file-upload: Tongda OA v11.8 api.ali.php - Arbitrary File Upload POC tongda-auth-bypass: Tongda OA 11.7 - Authentication Bypass POC tongda-contact-list-exposure: Tongda OA v2014 Get Contactlistt - Sensitive Information Disclosure POC tongda-getdata-rce: Tongda OA v11.9 getadata - Remote Code Execution POC tongda-getway-rfi: Tongda OA v11.8 getway.php - Remote File Inclution POC tongda-insert-sqli: Tongda OA v11.6 Insert Parameter - SQL Injection POC tongda-login-code-authbypass: Tongda OA v11.8 logincheck_code.php - Authentication Bypass POC tongda-meeting-unauth: Tongda OA Meeting - Unauthorized Access POC tongda-report-func-sqli: Tongda OA v11.6 report_bi.func.php - SQL injection POC tongda-video-file-read: Tongda OA V2017 Video File - Arbitrary File Read POC tongdaoa-auth-bypass: Tongda OA - Authentication Bypass 通达OA /get_columns.php SQL 注入漏洞