References https://www.cnblogs.com/fuchangjiang/p/17713330.html https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/%E7%B4%AB%E5%85%89%E6%A1%A3%E6%A1%88%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-upload.html-%E5%90%8E%E5%8F%B0%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/2048247.html https://stack.chaitin.com/poc/detail/3146 https://cn-sec.com/archives/2012995.html https://github.com/eeeeeeeeee-code/POC https://www.saury.net/poc-navigation
Related VulnerabilitiesPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoC全程云OA /oa/Common/WF/WorkFlow/WorkFlow.asmx SQL 注入漏洞孚盟云CRM WorkFlowHandler.ashx 存在SQL注入漏洞PoCargo-workflows-unauth: Argo Workflows - Unauthenticated DashboardPoCdagu-rce: Dagu Workflow Engine - Remote Code ExecutionPoC用友 NC /portal/pt/servlet/workflowImageServlet/doPost SQL 注入漏洞PoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞紫光软件系统有限公司 -- 紫光电子档案管理系统存在目录遍历Argo Workflows 需授权 路径遍历漏洞PoCCVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)亿赛通电子文档安全管理系统 /CDGServer3/3g/WorkFlowAction;Servicelogin SQL 注入漏洞