References https://qkl.seebug.org/vuldb/ssvid-91050 http://wooyun.2xss.cc/bug_detail.php?wybug_id=wooyun-2015-0150077 https://github.com/boy-hack/w9scan/blob/master/plugins/jdeas/2621.py https://github.com/bigblackhat/oFx/blob/main/docs/POCList.md https://www.mywjh.cn:2000/%E5%B7%A5%E5%85%B7%E8%BD%AF%E4%BB%B6/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/OA-EXPTOOL/main/kingdee/%E9%87%91%E8%9D%B6OA_path_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD.py https://qkl.seebug.org/appdir/Kingdee
Related VulnerabilitiesMeshery /api/system/fileDownload 文件读取漏洞PoC宏景系统 /templates/attestation/../../servlet/performance/fileDownLoad SQL 注入漏洞汉王e脸通综合管理平台 /manage/personnel/fileDownload.do 文件读取漏洞Eking管理易系统 /FileDownload.ihtm 文件读取漏洞金和OA /c6/JHSoft.Web.CustomQuery/FileDownLoad.aspx 文件读取漏洞Citrix ADC & Citrix Gateway /rapi/filedownload 路径存在任意文件读取漏洞金蝶OA /add_folder.jsp 路径 current_file_id 参数存在SQL注入漏洞金蝶OA /flow_performance_view_case_modify.jsp 路径存在SQL注入漏洞金蝶OA /get_one_view_case.jsp 路径存在SQL注入漏洞金蝶OA /netcom_out_rfile_submit.jsp 路径 netcom_id 参数存在SQL注入漏洞