References https://github.com/adysec/POC/blob/main/wpoc/%E4%B9%9D%E6%80%9DOA/%E4%B9%9D%E6%80%9DOA%E6%8E%A5%E5%8F%A3WebServiceProxy%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/DVB-2024-6705.html https://github.com/szjr123/JiusiOAExploitTool https://ddpoc.com/DVB-2024-7941.html https://cn-sec.com/archives/tag/%E4%B9%9D%E6%80%9Doa https://zone.ci/aliyun/ali_nonvd/265105.html https://blog.csdn.net/idhalashao/article/details/143893436 https://cn-sec.com/archives/4178319.html
Related VulnerabilitiesPoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞九思OA /jsoa/OfficeServer 文件上传漏洞PoCjiusi-oa-userlist3g-sqli: 九思OA软件user_list_3g.jsp存在SQL注入九思OA /jsoa/services/AppService.AppServiceHttpSoap12Endpoint/ XML 外部实体注入漏洞九思OA SAVEFILE 接口存在文件上传覆盖漏洞九思OA OfficeServer存在SQL注入漏洞九思OA AppService XXE漏洞PoC九思OA /jsoa/dl.jsp 文件读取漏洞九思协同办公系统 /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr 存在SQL注入漏洞