References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office-uploadify.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/pursue-security/p/17677400.html https://mrxn.net/jswz/eoffice-webservice-upload-rce.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office-uploadfile.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://xxzx.aku.edu.cn/info/1222/2054.htm https://peiqi.wgpsec.org/wiki/oa/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA%20E-Office%20OfficeServer.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.html https://cloud.tencent.com/developer/article/2118444 https://www.ctfiot.com/140787.html https://cn-sec.com/archives/1952621.html https://zhuanlan.zhihu.com/p/1932214870562047555 https://www.gm7.org/archives/32778 https://update.nsfocusglobal.com/update/listNewipsDetail/v/rule5.6.11_v2
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page Exposure上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-68509: User Submitted Posts <= 20251121 - Unauthenticated Open Redirect红海云 /RedseaPlatform/submitStWasAssessDept/StWasAssessDept.mob SQL 注入漏洞PoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting用友 U8Cloud /u8cloud/api/hrta/returnaway/submit SQL 注入漏洞