[add] Seeyon_OA_Fastjson_loginController_do_RCE

This commit is contained in:
gaopeng2 2021-07-07 16:47:49 +08:00
parent 0fe2d1b829
commit 971289f1e9
2 changed files with 25 additions and 0 deletions

View File

@ -0,0 +1,25 @@
# Seeyon OA Fastjson loginController.do RCE
The old version of Seeyon OA software (below V8.0, V8.0 was released on June 11, 2020) integrated Fastjson component has a deserialization vulnerability
**Affected Version**:
```json
Seeyon OA V7.1、V7.1SP1
Seeyon OA V7.0、V7.0SP1、V7.0SP2、V7.0SP3
Seeyon OA V6.1、V6.1SP1、V6.1SP2
Seeyon V6.0、V6.0SP1
Seeyon V5.6、V5.6SP1
```
**FOFA query rule**: [app="致远互联-OA"](https://fofa.so/result?qbase64=YXBwPSLoh7Tov5zkupLogZQtT0Ei)
# Demo
![](Seeyon_OA_Fastjson_loginController_do_RCE.gif)

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.0 MiB