漏洞描述 WPS Office存在代码执行漏洞,攻击者利用本漏洞专门构造出恶意文档,受害者打开该文档并执行相应操作后,才会联网从远程服务器下载恶意代码到指定目录并执行,前提是系统当前用户对该目录具备写权限,攻击者进而控制其电脑。
相关漏洞推荐 万户ezOFFICE协同平台 /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../modules/hrm/report/customize/checkSQL_httprequest.jsp SQL 注入漏洞 POC 普华科技 PowerPMS /PowerPlat/FormXml/DocFile/OfficeService.aspx 文件读取漏洞 普华 PowerPMS OfficeService.aspx SQL注入漏洞 POC PageOffice /sealimage.zz 文件读取漏洞 POC PageOffice /loginseal.zz 默认口令漏洞 泛微 E-Office /E-mobile/create/ajax_do.php 存在SQL注入漏洞 泛微 E-Office /E-mobile/diarydo.php存在SQL注入漏洞 e-office-v10-officeserver-upload: 泛微OA E-Office OfficeServer.php 任意文件上传漏洞 e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file upload 昂捷 ERP /EnjoyRMIS_WS/WS/OA/CWSOffice.asmx SQL 注入漏洞 昂捷-CRM-CWSOffice.asmx SQL注入 泛微E-Office /general/crm/record/detail.php SQL 注入漏洞 POC CVE-2020-6171: CLink Office 2.0 - Cross-Site Scripting