References https://www.cnblogs.com/pursue-security/p/17685261.html https://peiqi.wgpsec.org/wiki/oa/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20OA%20test.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://zhuanlan.zhihu.com/p/501515796 https://www.pa55w0rd.online/yyoa/ https://stack.chaitin.com/poc/detail/724 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E8%87%B4%E8%BF%9COA-A6-test.jsp-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://disk.scan.cm/All_wiki/%E4%BD%A9%E5%A5%87PeiQi-WIKI-POC-2021-7-20%E6%BC%8F%E6%B4%9E%E5%BA%93/PeiQi_Wiki/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20OA%20test.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://s4e.io/tools/yonyou-u8-sql-injection-scanner https://github.com/li8u99/yonyou_exp_plus
Related VulnerabilitiesApache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-5562)Dozzle /api/notifications/test-webhook 服务器端请求伪造漏洞(CVE-2026-45298)BrightSign Digital Signage /speedtest SSRF 漏洞UniFi OS Server latest_package 命令执行漏洞(CVE-2026-34908/CVE-2026-34909/CVE-2026-34910)LiteLLM /mcp-rest/test/connection 代码执行漏洞(CVE-2026-42271/CVE-2026-48710)AJ-Report积木报表 /dataSet/testTransform;swagger-ui 代码执行漏洞 (CVE-2024-7314)友数聚CPAS审计管理系统V4 testOpenPDF 任意文件读取漏洞PoCCVE-2025-69411: ionCube Tester Plus <= 1.3 - Local File InclusionWifi-soft UniBox Controller /authentication/test_userlogin.php 命令执行漏洞NocoBase /api/flow_nodes:test 代码执行漏洞(CVE-2026-34156)AVideo /plugin/Live/test.php 服务器端请求伪造漏洞(CVE-2026-33502)PoC宏景系统 /templates/attestation/../../servlet/performance/fileDownLoad SQL 注入漏洞PoCCVE-2024-43283: Contest Gallery - Broken Access Control