漏洞描述 【漏洞对象】E-Weaver 【漏洞描述】E-Weaver泛微协同办公软件/iweboffice/officeserver.php文件OPTION参数存在文件读取漏洞,攻击者可以通过读取任意文件,如系统安装信息等导致网站处于极度不安全状态。
相关漏洞推荐 e-office-v10-officeserver-upload: 泛微OA E-Office OfficeServer.php 任意文件上传漏洞 e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file upload weaver-oa-workrelate-file-upload: Weaver OA Workrelate File Upload POC CVE-2016-2389: SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion POC CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File Inclusion POC CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition POC CVE-2021-33690: SAP NetWeaver Development Infrastructure - Server Side Request Forgery POC CVE-2023-2648: Weaver E-Office 9.5 - Remote Code Execution POC CVE-2023-2766: Weaver OA 9.5 - Information Disclosure POC CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization POC CNVD-2022-43245: Weaver OA XmlRpcServlet - Arbitary File Read POC CVE-2023-2766: Weaver OA 9.5 - Information Disclosure POC e-cology-e-office-officeserver-file-read: 泛微OA E-Office officeserver.php 任意文件读取漏洞