References https://ddpoc.com/DVB-2025-10225.html https://cn-sec.com/archives/2441298.html https://github.com/adysec/POC/blob/main/wpoc/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA-fileUpload.controller%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/DVB-2024-6862.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/1322032.html https://github.com/NET-Flowers/Wanhu-uploadfilecheck
Related VulnerabilitiesPoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞万户OA officeserver 任意文件上传漏洞万户OA informationmanager_upload.jsp 任意文件上传漏洞万户OA freemarkeService 远程命令执行漏洞万户 ezOFFICE WeiXin!callback.action XXE漏洞wanhu-evointerfaceservlet-unauth: 万户 OA 未授权访问获取所有账户密码wanhu-oa-documentedit-sqli: 万户OA DocumentEdit.jsp SQL注入漏洞万户OA /defaultroot/govezoffice/custom_documentmanager/smartUpload.jsp 文件上传漏洞万户OA checkSQL_httprequest 存在SQL注入漏洞