References https://github.com/adysec/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office10%E7%89%88%E6%9C%AC%E5%B0%8F%E4%BA%8Ev10.0_20240222%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md https://rivers.chaitin.cn/blog/cq9412h0lnechd242lpg https://blog.csdn.net/weixin_42353842/article/details/137151780 https://netc.shcmusic.edu.cn/2024/0329/c1811a50607/pagem.htm https://www.ctfiot.com/140787.html https://www.hnitns.com/index.php?id=214 https://zhuanlan.zhihu.com/p/691331028 https://it.nwpu.edu.cn/info/1023/1715.htm https://peiqif4ck.github.io/penetrationtest/2024/03/articles/b8f9d080e95e9930/ https://blog.csdn.net/nglj9527/article/details/139244549 https://swjtuhc.cn/m/html/xxhywlgl/detail/303632 https://www.sdaxcl.com/yaqfh/shownews.php?id=87 https://wlaq.njupt.edu.cn/2024/0329/c14800a258600/page.htm
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page Exposure上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞