Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

大佬,这个漏洞poc在哪里可以找到IWebOfficeService.php 未授权文件上传漏洞 #9

Open
m1cc0s0ft opened this issue Jun 24, 2024 · 6 comments

Comments

@m1cc0s0ft
Copy link

No description provided.

@aiapple97
Copy link
Collaborator

能说明一下是哪个应用的具体什么漏洞吗?

@m1cc0s0ft
Copy link
Author

@aiapple97
Copy link
Collaborator

好久之前,他们网上发布的补丁包分析的。当时/iWebOffice/OfficeServer.php和/iWebOffice/OfficeServer2.php这两个出来后,10版本这个路由下有类似的漏洞。

@m1cc0s0ft
Copy link
Author

好久之前,他们网上发布的补丁包分析的。当时/iWebOffice/OfficeServer.php和/iWebOffice/OfficeServer2.php这两个出来后,10版本这个路由下有类似的漏洞。

搭建环境复现时候发现一直返回500,请问大佬你有遇到?

@aiapple97
Copy link
Collaborator

具体版本号我忘了,但是21年以前的v10版本才可以

@m1cc0s0ft
Copy link
Author

具体版本号我忘了,但是21年以前的v10版本才可以

------WebKitFormBoundaryLpoiBFy4ANA8daew
Content-Disposition: form-data;name="FormData"

{'ATTACHMENTID':'sample','MIME':'doc','OPTION':'DOWNLOAD'}
------WebKitFormBoundaryLpoiBFy4ANA8daew-- 我用了这个正常也返回500,版本是v10,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants