Huang Yaoshi Pharmaceutical Management Software Arbitrary File Upload Vulnerability

Vulnerability

An arbitrary file upload vulnerability has been identified in Huang Yaoshi Pharmaceutical Management Software versions through 16.0. The issue arises in the UploadFile function within the XSDService.asmx file, where the fileName element can be manipulated to upload files with .asp extensions. This vulnerability allows attackers to upload arbitrary files and potentially execute them on the server.

Impact

Exploitation of this vulnerability allows for arbitrary file upload, which could lead to execution of uploaded files on the server.

Reproduction

To reproduce this vulnerability, send a SOAP request to the XSDService.asmx endpoint. In the UploadFile element, specify a .asp filename in the fileName element. The buffer element can be used to include a payload, such as a simple ASP script. Once the file is uploaded, it can be accessed from the Upload2015 directory on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.