漏洞描述 速达软件专注中小企业管理软件,产品涵盖进销存软件,财务软件,ERP软件,CRM系统,项目管理软件,OA系统,仓库管理软件等,是中小企业管理市场的佼佼者,提供产品、技术、服务等信息,百万企业共同选择。该系统存在Struts2代码执行漏洞,攻击者可通过该漏洞获取服务器权限。
相关漏洞推荐 POC CVE-2006-3392: Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure POC CVE-2011-3600: Apache OFBiz - XML External Entity Injection POC CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS POC CVE-2016-15043: WP Mobile Detector <= 3.5 - Unrestricted File Upload POC CVE-2017-11107: phpLDAPadmin <= 1.2.3 - Reflected XSS POC CVE-2017-17762: Episerver 7 - Blind XML External Entity Injection POC CVE-2017-18580: WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution POC CVE-2017-20192: Formidable Forms < 2.05.02 - Cross-Site Scripting POC CVE-2018-10245: AWStats <= 7.5 - Full Path Disclosure POC CVE-2018-6961: VMware NSX SD-WAN Edge - Command Injection POC CVE-2018-9206: Blueimp jQuery-File-Upload v9.22.0 - Unrestricted File Upload POC CVE-2019-11253: Kubernetes API Server - YAML Parsing DoS (Billion Laughs) POC CVE-2019-15823: WPS Hide Login <= 1.5.2.2 - Login Page Bypass