1
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

[漏洞通告]通达OA任意文件上传并利用文件包含导致远程代码执行漏洞(0day)

1
Posted at

漏洞描述

通达OA是一套办公系统.近日通达OA官方在其官方论坛披露了近期一起通达OA用户服务器遭受勒索病毒攻击事件并发布了多个版本的漏洞补丁.
经过亚信安全网络攻防实验室分析,该0day漏洞真实存在,漏洞类型为任意文件上传,受影响的版本存在文件包含漏洞.成功授权的远程攻击者可以通过精心构造的请求包进行文件包含并触发远程代码执行.

漏洞编号

漏洞威胁等级

高危

受影响范围

V11版
2017版
2016版
2015版
2013增强版
2013版

漏洞验证

image.png

修复建议

及时更新漏洞补丁
http://www.tongda2000.com/news/673.php

时间轴

[0] 2020/03/13 通达OA论坛发布紧急通知
[1] 2020/03/17 亚信安全网络攻防实验室分析&复现该漏洞并发布漏洞通告

Reference

http://club.tongda2000.com/forum.php?mod=viewthread&tid=128372
http://club.tongda2000.com/forum.php?mod=viewthread&tid=128377

1
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
1
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?