近來(lái),公司上線新oa,找了一堆漏洞,記之。
注入
問(wèn)題出再
***/services/MobileService?wsdl
**.**.**.**/weaver/weaver.email.FileDownloadLocation?download=1&fileid=-2
**.**.**.**/pweb/careerapply/HrmCareerApplyPerEdit.jsp?id=1
**.**.**.**/pweb/careerapply/HrmCareerApplyPerView.jsp?id=1
**.**.**.**/pweb/careerapply/HrmCareerApplyWorkEdit.jsp?id=1
**.**.**.**/pweb/careerapply/HrmCareerApplyWorkView.jsp?id=1
**.**.**.**/web/careerapply/HrmCareerApplyPerEdit.jsp?id=1
**.**.**.**/web/careerapply/HrmCareerApplyPerView.jsp?id=1
**.**.**.**/web/careerapply/HrmCareerApplyWorkEdit.jsp?id=1
**.**.**.**/web/careerapply/HrmCareerApplyWorkView.jsp?id=1
**.**.**.**/meeting/Maint/MeetingTypeCheck.jsp?typename=aaa111&id=1
**.**.**.**/page/element/news/more.jsp?ebaseid=news&eid=1123
**.**.**.**/web/careerapply/HrmCareerApplyAdd.jsp?careerid=1