References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA-ucpcLogin%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/fuchangjiang/p/17699582.html https://blog.csdn.net/qq_39342001/article/details/137350007 https://netc.shcmusic.edu.cn/2023/0911/c1811a48785/page.htm https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/%E8%87%B4%E8%BF%9Coa/%E8%87%B4%E8%BF%9COA%20A8%20%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E4%BF%AE%E6%94%B9%E6%BC%8F%E6%B4%9E/ https://github.com/AboSteam/POPC/blob/main/%E8%87%B4%E8%BF%9COA%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E4%BF%AE%E6%94%B9%E6%BC%8F%E6%B4%9E.md https://stack.chaitin.com/vuldb/detail/6eec0895-432a-471a-9f70-ceb3cc9bb6ff https://cn-sec.com/archives/2616530.html https://zhuanlan.zhihu.com/p/656081347 https://www.ha.edu.cn/upload/202309/13/202309131001280437.pdf
Related Vulnerabilities致远 OA /seeyon/officeservlet 信息泄露漏洞PoC致远OA /seeyon/rest/m3/common/system/properties 信息泄露漏洞致远互联 致远OA personalBind 任意用户密码修改漏洞致远OA rest接口 前台密码重置漏洞PoCCNVD-2019-19299: 致远OA A8 htmlofficeservlet Remote Code ExecutionPoCCNVD-2020-62422: 致远oa系统存在任意文件读取漏洞PoCseeyon-a6-config-disclosure: 致远OA A6 config.jsp 敏感信息泄漏漏洞PoCseeyon-a6-createmysql-disclosure: 致远OA A6 createMysql.jsp 数据库敏感信息泄露PoCseeyon-a6-setextno-sql-inject: 致远OA A6 setextno.jsp SQL注入漏洞PoCseeyon-m1-usertokenservice-rce: 致远OA M1 server 反序列化命令执行漏洞PoCseeyon-management-default-password: 致远OA存在默认口令导致敏感信息泄露PoCseeyon-oa-ajax-fileupload: 致远OA ajax.do 任意文件上传