References https://www.cnblogs.com/pursue-security/p/17673809.html https://github.com/ibaiw/2023Hvv/blob/main/%E6%B3%9B%E5%BE%AE%20E-Cology%20%E6%9F%90%E7%89%88%E6%9C%AC%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20POC https://www.ddpoc.com/DVB-2024-6910.html https://bbs.decoyit.com/thread-592-1-1.html https://github.com/0day404/HV-2024-POC/blob/main/%E6%9F%90%E5%BE%AE%20E-Cology%20%E6%9F%90%E7%89%88%E6%9C%AC%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/1950510.html https://stack.chaitin.com/vuldb/detail/8c8fbd7b-3339-4bee-8af0-c029c24aa389 https://rivers.chaitin.cn/blog/cqli76h0lnec5jjug6hg
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞泛微-Ecology10 getFieldValueFun SQL注入漏洞泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞PoCecology-execforstr-rce: Weaver Ecology ExecForStr Remote Command ExecutionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information Disclosure泛微E-ecology 10 /papi/file/module/upload SQL 注入漏洞泛微 E-Cology /hrm/hrm_e9/orgChart/js/jquery/plugins/jqueryFileTree/connectors/jqueryFileTree.jsp 目录遍历漏洞泛微ecology10 存在sql注入漏洞泛微E-Cology9 /services/WorkPlanService SQL 注入漏洞PoCchanjet-crm-sqli: Chanjet CRM - SQL Injection