漏洞描述 通达oa办公系统为您提供移动办公,微信办公,协同办公,流程管理,信息门户,知识管理,任务项目,系统集成,费控管理等,全面提高工作效率。 通达oa办公系统存在任意文件上传漏洞,并且可配合文件包含导致任意代码执行,攻击者可在服务器端执行任意代码,写入后门,获取服务器权限,进而控制整个web服务器。
相关漏洞推荐 POC tongda-action-uploadfile: Tongda OA v2017 action_upload - Arbitrary File Upload POC tongda-api-file-upload: Tongda OA v11.8 api.ali.php - Arbitrary File Upload POC tongda-auth-bypass: Tongda OA 11.7 - Authentication Bypass POC tongda-contact-list-exposure: Tongda OA v2014 Get Contactlistt - Sensitive Information Disclosure POC tongda-getdata-rce: Tongda OA v11.9 getadata - Remote Code Execution POC tongda-getway-rfi: Tongda OA v11.8 getway.php - Remote File Inclution POC tongda-insert-sqli: Tongda OA v11.6 Insert Parameter - SQL Injection POC tongda-login-code-authbypass: Tongda OA v11.8 logincheck_code.php - Authentication Bypass POC tongda-meeting-unauth: Tongda OA Meeting - Unauthorized Access POC tongda-report-func-sqli: Tongda OA v11.6 report_bi.func.php - SQL injection POC tongda-video-file-read: Tongda OA V2017 Video File - Arbitrary File Read POC tongdaoa-auth-bypass: Tongda OA - Authentication Bypass 通达OA /get_columns.php SQL 注入漏洞