References https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/vulnerability/yonyou-nc-ncmessageservlet-rce.yaml https://s4e.io/tools/ufida-nc-remote-code-execution https://rivers.chaitin.cn/vuldb/591a76df-7c85-4ed7-8f63-5be7548b3bb3 https://fliggyaa/fscanpoc https://github.com/emadshanab/goby-poc/blob/main/Yonyou-NC-BaseApp-UploadServlet-Deserialization-RCE.json https://cn-sec.com/archives/2102611.html https://rivers.chaitin.cn/blog/cq70jnqp1rhtmlvvdocg https://github.com/hkxueqi/YonyouNc-UNSERIALIZE-scan
Related Vulnerabilities关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告PoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization用友U8Cloud MailApproveServlet存在SQL注入漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC Cloud及YonBIP高级版系统的datacollectservlet接口漏洞安全通告关于U8cloud所有版本XChangeServlet接口存在SQL注入漏洞的安全公告用友 U8 Cloud ThinApproveServlet SQL 注入漏洞鼎游票务系统 /system/ImageViewServlet 文件读取漏洞科荣AIO管理系统 /ReportServlet getFileList 目录遍历漏洞用友U8 Cloud /servlet/~uap/nc.merp.bs.NCMERPServlet XML 外部实体注入漏洞PoC用友 U8 Cloud /service/~uap/nc.bs.pf.pub.MailApproveServlet SQL 注入漏洞PoCCAREL Boss Mini /boss/servlet/document 文件包含漏洞(CVE-2023-3643)