Jinher oa是Jinher公司的企业应用软件。 Jinher OA 1.0版本存在安全漏洞,该漏洞源于对文件/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx中参数httpOID的错误操作,可能导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: SQL injection in PlanGiveOut.aspx httpOID parameter confirmed — PROOF_7480a654d20b9102 extracted via UNION SELECT
No comments yet