References https://cn-sec.com/archives/2529836.html https://www.ddpoc.com/DVB-2024-6107.html https://github.com/szjr123/JiusiOAExploitTool https://cn-sec.com/archives/2462765.html https://download.csdn.net/blog/column/11458669/136351240 https://github.com/y1hub/poc_exp https://blog.csdn.net/idhalashao/article/details/143893436
Related VulnerabilitiesPoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞九思OA /jsoa/OfficeServer 文件上传漏洞PoCjiusi-oa-userlist3g-sqli: 九思OA软件user_list_3g.jsp存在SQL注入九思OA /jsoa/services/AppService.AppServiceHttpSoap12Endpoint/ XML 外部实体注入漏洞九思OA SAVEFILE 接口存在文件上传覆盖漏洞九思OA OfficeServer存在SQL注入漏洞九思OA AppService XXE漏洞PoC九思OA /jsoa/dl.jsp 文件读取漏洞九思协同办公系统 /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr 存在SQL注入漏洞