References https://ho1l0w-by.github.io/2023/09/21/Smartbi%E7%B3%BB%E5%88%97%E6%BC%8F%E6%B4%9E%E8%AF%A6%E8%A7%A3%EF%BC%9A/ https://www.rksec.cn/news_detail/144.html https://stack.chaitin.com/vuldb/detail/a610bea1-cde7-4c5a-97e7-cf885280458f https://qkl.seebug.org/vuldb/ssvid-99716 https://zhuanlan.zhihu.com/p/651907254 https://www.secrss.com/articles/58121?app=1 https://x.threatbook.com/v5/article?threatInfoID=52904 https://www.snakin.top/posts/smartbi%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9Ev11/ https://blog.csdn.net/qq_53003652/article/details/135069768 https://www.cnvd.org.cn/flaw/show/CNVD-2021-20219 https://github.com/izj007/wechat/blob/main/articles/%5B%E5%B1%B1%E6%B5%B7%E4%B9%8B%E5%85%B3%5D-2023-8-3-%E3%80%90%E5%A4%8D%E7%8E%B0%E3%80%91Smartbi%20%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%E8%AF%A6%E7%BB%86%E5%88%86%E6%9E%90.md http://www.sxxdckj.com/cms/a/Smartbi-setEngineAddress-quan-xian-rao-guo-lou-dong.html
Related VulnerabilitiesPoCSmartbi /imageimport.jsp 存在任意文件上传smartbi-smartbi-bi-readfile: Smartbi smartbi_bi 任意文件读取Smartbi /vision/share.jsp 权限绕过漏洞Smartbi 远程代码执行漏洞PoCsmartbi-address-auth-bypass: Smartbi 权限绕过漏洞PoCsmartbi-bypass-builtin-user-login: Smartbi Default User Weak PasswordPoCsmartbi-changepassword-bypass: Smartbi修改用户密码PoCsmartbi-db2-biconfigservice-rce-temp: Smartbi DB2 RCEPoCsmartbi-db2-biconfigservice-rce: Smartbi DB2 RCEPoCsmartbi-unauthenticated-sqli: SmartBi 全版本 SQl 注入PoCsmartbi-windowunloading-other: Smartbi 远程代码执行漏洞PoCsmartbi-default-login: SmartBI - Default Login