用友某系统多处注入漏洞打包

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: wooyun搜了一下,没有人提,来一发。 ### 详细说明: 首先,该接口是无需权限访问的。 已http://**.**.**.**/bugs/wooyun-2010-0178322为例: **.**.**.**:8080/uapws/service/nc.itf.bd.crm.ICurrtypeExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IInvbasdocExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IMeasdocExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IInvclExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.ICustomerExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IAreaclExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.ICustomerImportToNcService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.ICorpExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IPsndocExportToCrmService?wsdl **.**.**.**:8080/uapws/service/nc.itf.bd.crm.IUserExportToCrmService?wsdl 均存在注入 [<img src="https://images.seebug.org/upload/201604/1818364061df662b74dbcb19d1e8de8062e9ac5e.png" alt="04184.png"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息