泛微eoffice login_other.php 注入漏洞

2021-01-19 泛微eoffice PoC No

Description

泛微e-office是泛微公司面向中小型组织推出的OA产品,简单易用高效,部署快、投资少。提供免费试用体验。login_other.php文件auth参数存在sql注入,黑客可以利用该注入点获取数据库敏感信息,由于泛微E-Office数据库用户默认为root,可以直接Getshell

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities