References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E4%B8%87%E6%88%B7OA-showResult.action-%E5%90%8E%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3filesendcheck_gd.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://mrxn.net/jswz/defaultroot-ezOFFICE-selectPopTable-sqli.html https://cloud.tencent.com/developer/article/2443508 https://www.secevery.com/toBugInfo?id=1878757606061555713 https://www.cnblogs.com/pursue-security/p/17764549.html https://github.com/Threekiii/Awesome-POC/blob/master/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E4%B8%87%E6%88%B7OA%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/2461567.html https://qkl.seebug.org/vuldb/ssvid-96185 https://mrxn.net/jswz/defaultroot-ezOFFICE-ajax_checkUserNum-sqli.html https://wy.zone.ci/bug_detail.php?wybug_id=wooyun-2014-064031 https://peiqi.wgpsec.org/wiki/oa/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://www.ddpoc.com/DVB-2023-5689.html
Related VulnerabilitiesPoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞万户OA officeserver 任意文件上传漏洞万户OA informationmanager_upload.jsp 任意文件上传漏洞万户OA freemarkeService 远程命令执行漏洞万户OA /defaultroot/yzConvertFile/file2Html.controller 任意文件上传漏洞万户 ezOFFICE WeiXin!callback.action XXE漏洞wanhu-evointerfaceservlet-unauth: 万户 OA 未授权访问获取所有账户密码wanhu-oa-documentedit-sqli: 万户OA DocumentEdit.jsp SQL注入漏洞万户OA /defaultroot/govezoffice/custom_documentmanager/smartUpload.jsp 文件上传漏洞