References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%BA%A2%E5%B8%86OA/%E7%BA%A2%E5%B8%86ioffice-udfGetDocStep.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://stack.chaitin.com/vuldb/detail/51b8b42b-74f8-4226-95d6-4cd0c7128c33 https://blog.csdn.net/qq_33608000/article/details/136735113 https://avd.aliyun.com/detail?id=AVD-2021-895091 https://www.cnvd.org.cn/flaw/show/CNVD-2021-24392 https://www.aqtd.com/nd.jsp?id=4869 https://www.ddpoc.com/DVB-2024-6355.html https://cn-sec.com/archives/2525713.html https://zone.ci/aliyun/ali_highrisk/306019.html
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page Exposure上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞