用友FE协作办公系统FILE协议文件读取漏洞(通杀全版本)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 用友FE协作办公系统某处协议处理接口未过滤file://协议,导致任意文件读取漏洞,通杀全版本 ### 详细说明: ``` web.xml有如下配置: <servlet> <servlet-name>ProxyServletUtil</servlet-name> <servlet-class>fe.witmanage.service.ProxyServletUtil</servlet-class> </servlet> <servlet-mapping> <servlet-name>ProxyServletUtil</servlet-name> <url-pattern>/ProxyServletUtil</url-pattern> </servlet-mapping> ``` [<img src="https://images.seebug.org/upload/201411/072215468809be612ef8d59a43fd660cb1c5e4ef.png" alt="0.PNG" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201411/072215468809be612ef8d59a43fd660cb1c5e4ef.png) ``` ProxyServletUtil.java源码如下: /* */ public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException /* */ { /* 23 */ String urlString = request.getParameter("url"); /* 24 */ writeResponse(response, urlString); /* */ } /* */ /* */ private void writeResponse(HttpServletResponse response, String urlString) throws ServletException { /* */ try { /* 29...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息