泛微e-office...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 漏洞信息: 泛微e-office是泛微公司面向中小型组织推出的OA产品,简单易用高效,部署快、投资少。提供免费试用体验。至今已为超过一万家客户提供方便高效的办公体验。 泛微e-office存在任意文件上传漏洞导致敏感信息泄漏。 ### 漏洞分析: 漏洞存在于E-mobile/Data/downfile.php ``` $fileurl = $_REQUEST['url']; $sessionstr = $_REQUEST['sessionkey']; $strexplode = explode( ",", $sessionstr ); $sessionkey = $strexplode[0]; $curr_user_id = $strexplode[1]; $rooturl = "http://".$_SERVER['HTTP_HOST']; $checkurl = explode( "/", $fileurl ); if ( $checkurl[1] == "flowimg" ) { $url = $rooturl."/E-mobile/flowimg.php?RUN_ID=".$checkurl[2]."&FLOW_ID=".$checkurl[3]; $type = "png"; } else if ( $checkurl[1] == "freeflowimg" ) { $url = $rooturl."/E-mobile/flow/freeflowimg.php?RUN_ID=".$checkurl[2]."&FLOW_ID=".$checkurl[3]; $type = "png"; } else { $url = $rooturl.$fileurl; $filetype = pathinfo( $fileurl ); $type = $filetype['extension']; } if ( $type == "css" ) { header( "Content-Type: text/css" ); } else if ( $type == "js" ) { header( "Content-Type: application/javascript" ); } else if ( $type == "jpg" || $type ==...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息