References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E9%87%91%E8%9D%B6OA-Apusic%E5%BA%94%E7%94%A8%E6%9C%8D%E5%8A%A1%E5%99%A8(%E4%B8%AD%E9%97%B4%E4%BB%B6)-server_file-%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md https://www.modb.pro/db/120388 https://github.com/Threekiii/Awesome-POC/blob/master/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E9%87%91%E8%9D%B6OA%20server_file%20%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md https://zhuanlan.zhihu.com/p/378536524 https://disk.scan.cm/All_wiki/%E4%BD%A9%E5%A5%87PeiQi-WIKI-POC-2021-7-20%E6%BC%8F%E6%B4%9E%E5%BA%93/PeiQi_Wiki/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E9%87%91%E8%9D%B6OA/%E9%87%91%E8%9D%B6OA%20server_file%20%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md?hash=6b2qz0V8 https://cn-sec.com/archives/1716188.html https://www.duoweizhe.com/dwz_ldfx/48.html https://avd.aliyun.com/detail?id=AVD-2021-890093 https://github.com/xinyisleep/pocscan/blob/main/%E9%87%91%E8%9D%B6OA-EAS%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86.py
Related VulnerabilitiesPoCkingdee-oa-apusic-server-file-traversal: 金蝶OA Apusic应用服务器(中间件) server_file 目录遍历金蝶OA /add_folder.jsp 路径 current_file_id 参数存在SQL注入漏洞金蝶OA /flow_performance_view_case_modify.jsp 路径存在SQL注入漏洞金蝶OA /get_one_view_case.jsp 路径存在SQL注入漏洞金蝶OA /netcom_out_rfile_submit.jsp 路径 netcom_id 参数存在SQL注入漏洞金蝶OA /addmsg.jsp 路径存在SQL注入漏洞金蝶OA 存在SQL注入漏洞金蝶OA /save_file_property.jsp 路径存在SQL注入漏洞金蝶OA /set_submit.jsp 路径 portlet_id 参数存在SQL注入漏洞金蝶OA /document/view.jsp 路径 portal_id 参数存在SQL注入漏洞