用友PDM Professional全版本通用型配置不当导致getshell

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: rt ### 详细说明: 涉及: 用友PDM Professional 7.5 用友PDM Professional 6.5SP1 用友PDM Professional 7.2 用友PDM Professional 7.0 用友PDM Professional 6.0 详细看案例。 jboss未授权访问导致getshell ``` None ``` ### 漏洞证明: [<img src="https://images.seebug.org/upload/201506/192121208536f6b10e8349dde2952ba9a3ca325a.jpg" alt="aaaaaaa1111111111111111.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/192121208536f6b10e8349dde2952ba9a3ca325a.jpg) [<img src="https://images.seebug.org/upload/201506/192131059bf369137e52fb90b117d770308fc370.jpg" alt="aaaaaaaaaa22222222222222.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/192131059bf369137e52fb90b117d770308fc370.jpg) [<img src="https://images.seebug.org/upload/201506/19213119469f1dbb75b106f7d64d09fd4667d9c4.jpg" alt="aaaaaaa3333333333.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/19213119469f1dbb75b106f7d64d09fd4667d9c4.jpg)

0%
暂无可用Exp或PoC
当前有0条受影响产品信息