'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2025-07-22 | |
| Rule Name: | Landry EKP dataxml.tmpl Remote Command Execution Vulnerability | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Landry is a professional provider of digital office services in China. It is the only OA vendor invested by Alibaba DingTalk and the first strategic partner of Alibaba Cloud in the field of knowledge management and collaboration. There is a remote command execution vulnerability in the dataxml.tmpl of the Landry OA system. Attackers can execute arbitrary commands through this vulnerability, resulting in the server being compromised. | |
| Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |