References https://cn-sec.com/archives/786526.html https://github.com/bmth666/Yongyou-Unserialize-plus https://github.com/HimmelAward/Goby_POC/blob/main/README.md http://www.bmth666.cn/2023/09/08/%E7%94%A8%E5%8F%8BNC6-5-%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1/index.html https://github.com/fliggyaa/fscanpoc https://cn-sec.com/archives/2102611.html https://github.com/ibaiw/2024Hvv/blob/main/%E7%94%A8%E5%8F%8B%20U8%20cloud%20MonitorServlet%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
Related Vulnerabilities关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告PoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization用友U8Cloud MailApproveServlet存在SQL注入漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC Cloud及YonBIP高级版系统的datacollectservlet接口漏洞安全通告关于U8cloud所有版本XChangeServlet接口存在SQL注入漏洞的安全公告用友 U8 Cloud ThinApproveServlet SQL 注入漏洞鼎游票务系统 /system/ImageViewServlet 文件读取漏洞科荣AIO管理系统 /ReportServlet getFileList 目录遍历漏洞用友U8 Cloud /servlet/~uap/nc.merp.bs.NCMERPServlet XML 外部实体注入漏洞PoC用友 U8 Cloud /service/~uap/nc.bs.pf.pub.MailApproveServlet SQL 注入漏洞PoCCAREL Boss Mini /boss/servlet/document 文件包含漏洞(CVE-2023-3643)