Goby/json/Weaver-OA-E-Cology-Workflow...

44 lines
1.2 KiB
JSON

{
"Name": "Weaver-OA E-Cology WorkflowServiceXml RCE",
"Description": "Weaver-OA E-Cology WorkflowServiceXml RCE",
"Product": "Weaver-OA",
"Homepage": "https://www.weaver.com.cn/",
"DisclosureDate": "2021-05-06",
"Author": "gaopeng2@baimaohui.net",
"FofaQuery": "app=\"Weaver-OA\" || header=\"ecology_JSessionid\"",
"GobyQuery": "app=\"Weaver-OA\" || header=\"ecology_JSessionid\"",
"Level": "3",
"Impact": "Arbitrary code execution,getshell",
"Recommendation": "upgrade version - https://www.weaver.com.cn/cs/securityDownload.html?src=cn",
"References": null,
"RealReferences": [
"https://mp.weixin.qq.com/s/C4C7kCBVt5gUFKocMPqVbA",
"https://www.anquanke.com/post/id/239865",
"https://www.weaver.com.cn/cs/securityDownload.html?src=cn"
],
"HasExp": true,
"ExpParams": [
{
"Name": "cmd",
"Type": "input",
"Value": "whoami"
}
],
"ExpTips": {
"Type": "",
"Content": ""
},
"ScanSteps": null,
"ExploitSteps": null,
"Tags": ["rce"],
"CVEIDs": null,
"CVSSScore": "N/A",
"AttackSurfaces": {
"Application": ["Weaver-OA"],
"Support": null,
"Service": null,
"System": null,
"Hardware": null
},
"Disable": false
}