References https://help.fanruan.com/finereport/edition-view-64033-0.html https://github.com/Threekiii/Awesome-POC https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E5%B8%86%E8%BD%AF%E6%8A%A5%E8%A1%A8-channel-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md https://cloud.tencent.com/developer/article/2443297 https://cn-sec.com/archives/3008988.html https://github.com/zan8in/wy876-POC/blob/main/%E5%B8%86%E8%BD%AF%E6%8A%A5%E8%A1%A8/%E5%B8%86%E8%BD%AF%E7%B3%BB%E7%BB%9FReportServer%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%AF%BC%E8%87%B4RCE.md https://blog.csdn.net/baidu_25299117/article/details/141258423
Related Vulnerabilities帆软报表存在未授权访问漏洞PoCCNVD-2018-04757: 帆软报表 V8 get_geo_json 任意文件读取漏洞PoCfanruan-finereport-fr-log-rce: 帆软 FineReport Fr Log RcePoCfanruan-oa-v9-designsavevg-upload-file: 帆软报表 V9 design_save_svg 任意文件覆盖文件上传PoCseeyon-fanruan-report-server-directory-travesal: 致远OA 帆软组件 ReportServer 目录遍历漏洞PoCfine-report-v9-file-upload: FineReport v9 Arbitrary File OverwritePoCfinereport-path-traversal: FineReport 8.0 - Local File InclusionPoCfinereport-sqli-rce: FineReport SQLi - Remote Code Execution致远OA-帆软报表组件 dbcommit 命令执行漏洞帆软pdf接口远程命令执行帆软报表 /report/v9/print/ie/pdf SQL注入漏洞PoC帆软 WebReport plugin_logdb JDBC 漏洞帆软报表远程命令执行漏洞