nuclei-templates/http/vulnerabilities/yonyou/yonyou-nc-info-leak.yaml

38 lines
1.4 KiB
YAML
Raw Normal View History

2023-09-15 14:29:07 +00:00
id: yonyou-nc-info-leak
info:
name: Yonyou UFIDA NC - Information Exposure
author: SleepingBag945
severity: medium
description: |
After logging in and visiting the address where the information was leaked, you will have permission to upload files. Then just go back to the homepage and view the published content directly.
reference:
- https://mp.weixin.qq.com/s/Lu6Zd9LP3PQsb8uzTIcANQ
- https://github.com/zhangzhenfeng/AnyScan/blob/master/AnyScanUI/AnyPoc/data/poc/bugscan/exp%EF%BC%8D2311.py
2024-09-10 09:08:16 +00:00
classification:
cpe: cpe:2.3:a:yonyou:ufida-nc:*:*:*:*:*:*:*:*
2023-09-15 14:29:07 +00:00
metadata:
2023-10-14 11:27:55 +00:00
verified: true
2023-09-15 14:29:07 +00:00
max-request: 1
2024-09-10 08:22:50 +00:00
vendor: yonyou
2024-09-10 09:08:16 +00:00
product: ufida-nc
fofa-query: app="用友-UFIDA-NC
2023-09-15 14:29:07 +00:00
tags: yonyou,nc,exposure
http:
- method: GET
path:
- "{{BaseURL}}/service/~iufo/com.ufida.web.action.ActionServlet?TableSelectedID&TreeSelectedID&action=nc.ui.iufo.release.InfoReleaseAction&method=createBBSRelease"
matchers-condition: and
matchers:
- type: word
words:
- "iufo/web/images/usericon.gif"
- "/iufo/web/images/tree/tree_plus.gif"
condition: and
- type: status
status:
2023-10-14 11:27:55 +00:00
- 200
2024-09-12 05:14:01 +00:00
# digest: 4a0a00473045022005c4dc979b85fa1e5f42260aa0436f5c3e5550411988b038e413ef099bf9cdb202210097bca43637fa10e68bf305e40a3bc45281afec75427581054f3aa50ee26ce088:922c64590222798bb761d5b6d8e72950