漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
Vulnerability Description
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters without any authentication, file type, extension, or content validation. Attackers can upload a JSP webshell by specifying a malicious filename and root filepath, with the uploaded file stored under the pictures directory and directly executed by the web server, resulting in unauthenticated remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-11-07 (UTC).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Yonyou KSOA 任意文件上传漏洞
Vulnerability Description
Yonyou ksoa是中国Yonyou公司的一款办公自动化软件。 Yonyou KSOA 9.0版本存在任意文件上传漏洞,该漏洞源于com.sksoft.bill.ImageUpload servlet 中存在未认证任意文件上传漏洞,攻击者无需身份验证、文件类型或内容验证,通过POST请求提交含恶意文件路径和文件名参数的请求,可上传JSP webshell并导致未认证远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A