References https://github.com/zan8in/pocwiki/blob/main/%E4%B8%87%E6%88%B7OA-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://qkl.seebug.org/vuldb/ssvid-91449 http://wy.zone.ci/bug_detail.php?wybug_id=wooyun-2014-067391 https://cn-sec.com/archives/17049.html https://www.ddpoc.com/DVB-2024-6862.html https://stack.chaitin.com/techblog/detail/180 https://qkl.seebug.org/appdir/ezOFFICE https://www.zixuephp.com/html/hkgf/2015_04/28356.html
Related VulnerabilitiesPoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞万户OA officeserver 任意文件上传漏洞万户OA freemarkeService 远程命令执行漏洞万户OA /defaultroot/yzConvertFile/file2Html.controller 任意文件上传漏洞万户 ezOFFICE WeiXin!callback.action XXE漏洞wanhu-evointerfaceservlet-unauth: 万户 OA 未授权访问获取所有账户密码wanhu-oa-documentedit-sqli: 万户OA DocumentEdit.jsp SQL注入漏洞万户OA /defaultroot/govezoffice/custom_documentmanager/smartUpload.jsp 文件上传漏洞万户OA checkSQL_httprequest 存在SQL注入漏洞