Post

Zhiyuan Oa A6 Config Jsp Sensitive Information Leakage Vulnerability

Zhiyuan Oa A6 Config Jsp Sensitive Information Leakage Vulnerability

Zhiyuan OA A6 config.jsp Sensitive information leakage vulnerability

Vulnerability Description

Zhiyuan OA A6 config.jsp page can be accessed unauthorized, resulting in a vulnerability for sensitive information leakage. The attacker can obtain sensitive information in the server through the vulnerability.

Vulnerability Impact

Zhiyuan OA A6

Network surveying and mapping

Vulnerability reappears

Login page

img

Verify POC

1
	/yyoa/ext/trafaxserver/SystemManage/config.jsp

img

This post is licensed under CC BY 4.0 by the author.