金蝶内部员工系统目录遍历、泄露服务器集群IP、财务收入报表等数据

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 配置错误导致遍历漏洞,监控log文件报告,可以找到关键sql语句 内部敏感数据遍历下载,服务器集群ip泄露,财务收入报表随意下载,危险程度自知! ### 详细说明: ``` http://kdeas.kingdee.com//easWebClient/ http://kdeas.kingdee.com/nap/ http://kdeas.kingdee.com//client/ http://global.kingdee.com/en/products/kis/ http://login.mykingdee.com/login?service=http%3A%2F%2Fkdeas.kingdee.com%3A7888%2Feasportal%2F %3Bjsessionid%3DwKjIVx7QUW4U0KJcrnuDNk71l-2rDge04rYA http://web20.kingdee.com/down http://kdeas.kingdee.com/easfiles/easdoc/files/ ``` http://www.kingdee.com/sitemap.xml 网站地图 配置错误导致遍历漏洞,监控log文件报告,可以找到关键sql语句 配置文件信息外露,代码泄露! ### 漏洞证明: [<img src="https://images.seebug.org/upload/201304/17105138dada7b9d56cd85ef3c4865341a2ebce6.jpg" alt="5.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201304/17105138dada7b9d56cd85ef3c4865341a2ebce6.jpg) [<img src="https://images.seebug.org/upload/201304/1710512782addc1ffba2f13bd971072278032491.jpg" alt="4.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息