References http://wy.zone.ci/bug_detail.php?wybug_id=wooyun-2015-0105535 https://www.cnblogs.com/AtesetEnginner/p/13185614.html https://www.ddpoc.com/DVB-2025-10133.html https://www.cnvd.org.cn/flaw/show/CNVD-2016-07263 http://wy.zone.ci/bug_detail.php?wybug_id=wooyun-2015-0105517 https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office%E7%B3%BB%E7%BB%9Fsms_page.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page Exposure上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞