References https://www.ddpoc.com/DVB-2025-9988.html https://github.com/Sec-Fork/POC-20250106/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0UniformEntry.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-19181).md https://www.cnblogs.com/0neOr2eR0/p/18723789 https://blog.csdn.net/qq_36618918/article/details/135485555 https://github.com/adysec/POC/blob/main/wpoc/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0rpt_listreport_definefield.aspx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/DVB-2024-5897.html https://mrxn.net/jswz/landray-eis-fl_define_edit-sqli.html https://cn-sec.com/archives/2544293.html https://xsx.tw/exploit/3430/ https://www.ddpoc.com/DVB-2023-5373.html
Related VulnerabilitiesPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoC蓝凌EIS智慧协同平台 /common/FI_SelEmp.aspx SQL 注入漏洞蓝凌EIS智慧协同平台 /Mobile/mobile_define.aspx/Getmobiles SQL 注入漏洞Langflow /api/v1/validate/code 代码执行漏洞(CVE-2026-0770)Langflow validate/code 存在授权远程代码执行漏洞(CVE-2026-0770)PoC蓝凌-EIS智慧协同平台 /third/DingTalk/Pages/DingTalkMessage.aspx SQL 注入漏洞PoCCVE-2026-0770: Langflow < 1.3.0 - Remote Code Execution via validate_code() exec()金和OA EpassValidate.aspx XXE漏洞金蝶云星空 /Kingdee.BOS.WebApi.ServicesStub.AuthService.ValidateLoginInfo.common.kdsvc 命令执行漏洞PoC蓝凌EIS智慧协同平台 /mail/mail_server.aspx/mail_xml XML 外部实体注入漏洞DataEase /de2api/datasource/validate 命令执行漏洞(CVE-2025-62420)