References https://github.com/theLSA/ecshop-getshell https://www.exploit-db.com/exploits/8548 https://medium.com/@knownsec404team/from-deserialization-to-type-confusion-vulnerability-record-an-instance-usage-of-ecshop-128a09225ecc https://www.ikow.cn/ecshop-payload/ https://www.cnblogs.com/mke2fs/p/11663856.html https://xuptsec.github.io/2018/09/18/%E4%BB%8ESQLi%E5%88%B0RCE-ecshop-2-x-3-x%E6%97%A0%E9%99%90%E5%88%B6getshell/ https://www.codemonster.cn/2018/09/10/2018-ecshop-rce-analyse/ https://zhuanlan.zhihu.com/p/3839035914 https://www.cnblogs.com/ichunqiu/p/9680973.html https://developer.aliyun.com/article/639000 http://joker-vip.github.io/2021/07/15/ECShop%202.x3.x%20SQL%E6%B3%A8%E5%85%A5%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/
Related VulnerabilitiesPoCCVE-2021-41460: ECShop 4.1.0 - SQL InjectionPoCCNVD-2020-58823: ecshop-delete-cart-goods-sqliPoCecshop-2x-sql-inject: ECShop 2.x/3.x SQL 注入/远程代码执行PoCecshop-collection-list-sqli: ECshop Collection List sqliPoCecshop-sqli: ECShop 2.x/3.x - SQL InjectionECShop 2.x 3.0 代码执行漏洞ecshop3.x 代码执行yii2_fecshop 跨站脚本漏洞ecshop2.x 代码执行ECShop 4.1.0 delete_cart_goods.php文件id参数SQL注入漏洞ECShop 本地文件包含漏洞ECShop user.php-宽字节注入漏洞ECShop search.php-SQL注入