漏洞描述 通达OA (0fice Anywhere网络智能办公系统)是由通达信科科技自主研发的协同办公自动化软件,是与中国企业管理实践相结合形成的综合管理办公平台。通达OA为各行业不同规模的众多用户提供信息化管理能力,包括流程审批、行政办公、日常事务、数据统计分析、即时通讯、移动办公等,帮助广大用户降低沟通和管理成本,提升生产和决策效率。通达OA /mysql/index.php存在未授权访问,攻击者可以不需要账号密码直接访问系统的phpmyadmin,造成敏感信息泄露。
相关漏洞推荐 POC tongda-action-uploadfile: Tongda OA v2017 action_upload - Arbitrary File Upload POC tongda-api-file-upload: Tongda OA v11.8 api.ali.php - Arbitrary File Upload POC tongda-auth-bypass: Tongda OA 11.7 - Authentication Bypass POC tongda-contact-list-exposure: Tongda OA v2014 Get Contactlistt - Sensitive Information Disclosure POC tongda-getdata-rce: Tongda OA v11.9 getadata - Remote Code Execution POC tongda-getway-rfi: Tongda OA v11.8 getway.php - Remote File Inclution POC tongda-insert-sqli: Tongda OA v11.6 Insert Parameter - SQL Injection POC tongda-login-code-authbypass: Tongda OA v11.8 logincheck_code.php - Authentication Bypass POC tongda-meeting-unauth: Tongda OA Meeting - Unauthorized Access POC tongda-report-func-sqli: Tongda OA v11.6 report_bi.func.php - SQL injection POC tongda-video-file-read: Tongda OA V2017 Video File - Arbitrary File Read POC tongdaoa-auth-bypass: Tongda OA - Authentication Bypass 通达OA /get_columns.php SQL 注入漏洞