某政府服务系统存在通用性两处任意文件上传可getshell

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 两处任意文件上传漏洞 ### 详细说明: 技术支持:邯郸市连邦软件发展有限公司 波及多家政务服务系统,可直接上传获取webshell。【声明:未做任何破坏】 两处任意文件上传: 第一处: ``` http://121.18.89.108/workplate/comm/xzsp/form/aspxforms/fzlist.aspx http://www.lxxzfwzx.com/workplate/comm/xzsp/form/aspxforms/fzlist.aspx http://www.wdxxzfwzx.com/workplate/comm/xzsp/form/aspxforms/fzlist.aspx http://www.gbdqyw.com/workplate/comm/xzsp/form/aspxforms/fzlist.aspx http://www.bdxzfw.cn/workplate/comm/xzsp/form/aspxforms/fzlist.aspx http://www.rzfwzx.gov.cn/workplate/comm/xzsp/form/aspxforms/fzlist.aspx ``` 第二处: ``` http://121.18.89.108/workplate/comm/attachment/list.aspx http://www.lxxzfwzx.com/workplate/comm/attachment/list.aspx http://www.wdxxzfwzx.com/workplate/comm/attachment/list.aspx http://www.gbdqyw.com/workplate/comm/attachment/list.aspx http://www.bdxzfw.cn/workplate/comm/attachment/list.aspx http://www.rzfwzx.gov.cn/workplate/comm/attachment/list.aspx ``` ### 漏洞证明: http://121.18.89.108/workplate/comm/xzsp/form/aspxforms/fzlist.aspx 直接上传,无任何过滤 [<img...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息