References https://cn-sec.com/archives/2828119.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93/%E6%96%B9%E6%AD%A3%E7%95%85%E4%BA%AB%E5%85%A8%E5%AA%92%E4%BD%93%E6%96%B0%E9%97%BB%E9%87%87%E7%BC%96%E7%B3%BB%E7%BB%9FimageProxy.do%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3548048.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93/%E6%96%B9%E6%AD%A3%E7%95%85%E4%BA%AB%E5%85%A8%E5%AA%92%E4%BD%93%E6%96%B0%E9%97%BB%E9%87%87%E7%BC%96%E7%B3%BB%E7%BB%9FaddOrUpdateOrg%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3585143.html http://www.aqtd.com/nd.jsp?id=7624 https://github.com/AboSteam/POPC https://zhuanlan.zhihu.com/p/1932214870562047555 https://gitea.com/Run0nceEx/POC https://www.secevery.com/toBugInfo?id=1875133730320596993
Related VulnerabilitiesPoC方正畅享全媒体采编系统 /newsedit/msg/cc.do 信息泄露漏洞PoCfounder-binary-do-sqli.yaml: 方正畅享全媒体采编系统 binary.do SQL注入PoCfounder-syn-do-inclosure: 方正畅享全媒体采编系统敏感信息泄露方正畅享全媒体采编系统 /newsedit/newsedit/xy/imageProxy.do 文件读取漏洞方正畅享全媒体采编系统 weixinMain.do XXE漏洞方正畅享全媒体采编系统 task.do 信息泄露漏洞方正畅享全媒体采编系统 outerfotobase/imageProxy.do SSRF漏洞方正畅享全媒体采编系统 xy/imageProxy.do SSRF漏洞方正畅享全媒体采编系统 reportCenter.do SQL注入漏洞方正畅享全媒体采编系统 BadClue 权限提升漏洞PoC方正畅享全媒体采编系统 getRemotePapers 权限绕过漏洞方正畅享全媒体采编系统 addOrUpdateUser XXE漏洞