0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

[漏洞预警]泛微ecology OA系统某接口存在数据库配置信息泄露漏洞

0
Posted at

漏洞描述

泛微e-cology OA系统某接口存在数据库配置信息泄露漏洞.攻击者可通过存在漏洞的页面并解密以后可获取到数据库配置信息.如果攻击者可直接访问数据库,则可直接获取用户数据,由于泛微e-cology默认数据库大多为MSSQL数据库,结合XPCMDSHELL将可直接控制数据库服务器.

漏洞威胁等级

根据亚信安全网络攻防实验室评估为中危

利用难度

高

影响范围

目前已知为8.100.0531,不排除其他版本

漏洞复现

使用payload进行验证

直接访问该页面将为DES加密以后的乱码

image.png

需要使用DES算法结合硬编码的key进行解密

image.png

修复建议

等待泛微官方进行修复
https://www.weaver.com.cn/

鸣谢

Lufei

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?