泛微OA某接口无需登录可执行任意SQL语句(附脚本)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 荒废了 啥都不会 找工作啊 ### 详细说明: 先以本地为例 http://localhost:8088/ws [<img src="https://images.seebug.org/upload/201602/261505325ad6cc962e7df590d4fbbe74ea888bca.jpg" alt="Snap67.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201602/261505325ad6cc962e7df590d4fbbe74ea888bca.jpg) ``` http://localhost:8088/ws/query?wsdl ``` [<img src="https://images.seebug.org/upload/201602/26150714fab2776e42d8c9cec5a3b1ed92c57412.jpg" alt="Snap68.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201602/26150714fab2776e42d8c9cec5a3b1ed92c57412.jpg) 竟然提示 ``` <faultstring>Unmarshalling Error: unexpected element (uri:"http://**.**.**.**/", local:"arg0"). Expected elements are &lt;{}arg1&gt;,&lt;{}arg0&gt; </faultstring> ``` 搜索 [<img src="https://images.seebug.org/upload/201602/2615181165d4a7c015b4eff03b1f690f41abe9cd.jpg" alt="Snap69.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息