References https://github.com/Threekiii/Awesome-POC/blob/master/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E4%B8%87%E6%88%B7OA%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://peiqi.wgpsec.org/wiki/oa/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://blog.csdn.net/qq_33608000/article/details/136642212 https://github.com/LittleBear4/OA-EXPTOOL/issues/18 https://cn-sec.com/archives/3933657.html https://github.com/Sec-Fork/POC-20241008/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7%20ezOFFICE%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5.md https://www.ddpoc.com/DVB-2023-5168.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7%20ezOFFICE%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5.md
Related VulnerabilitiesPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCchanjet-crm-sqli: Chanjet CRM - SQL InjectionPoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞万户OA officeserver 任意文件上传漏洞万户OA informationmanager_upload.jsp 任意文件上传漏洞万户OA freemarkeService 远程命令执行漏洞万户OA /defaultroot/yzConvertFile/file2Html.controller 任意文件上传漏洞万户 ezOFFICE WeiXin!callback.action XXE漏洞amtt-hiboss-language-sqli: 安美数字酒店宽带运营系统SQL注入漏洞