References http://xxhc.yzu.edu.cn/info/1096/9918.htm https://rivers.chaitin.cn/blog/cq949d10lnechd242ph0 https://www.venustech.com.cn/new_type/aqtg/20230807/26029.html https://avd.aliyun.com/detail?id=AVD-2023-4166 https://www.xsssql.com/article/566.html https://www.ctfiot.com/129210.html https://bbs.decoyit.com/thread-586-1-1.html https://wlaq.njupt.edu.cn/2023/0829/c14800a245709/page.htm https://github.com/anfugui/11111/blob/main/%E9%80%9A%E8%BE%BEOA%20sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2023-4166.md https://avd.aliyun.com/detail?id=AVD-2023-4166 http://nic.cqrk.edu.cn/2023_08/07_10/content-37229.html
Related Vulnerabilities通达OA v11.7 delete_cascade.php SQL 注入漏洞通达OA /general/reportshop/utils/upload.php 文件上传漏洞(CNVD-2021-21890)通达OA delete_seal.php SQL 注入漏洞(CVE-2023-4165)通达OA /pda/apps/report/getdata.php 文件上传漏洞通达OA delete_log.php SQL 注入漏洞(CVE-2023-4166)tongda-handle-sqli: 通达OA handle SQL注入tongda-v11-getdata-rce: 通达OA v11.9 getdata 任意命令执行漏洞PoCCVE-2023-4166-2: 通达OA seal_manage SQL 注入