References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Cology%E6%8E%A5%E5%8F%A3WorkflowServiceXml%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cloud.tencent.com/developer/article/2437209 https://www.secrss.com/articles/68103?app=1 https://rivers.chaitin.cn/blog/cq940v90lnechd242lh0 https://zhuanlan.zhihu.com/p/653810927 https://wlaq.njupt.edu.cn/2024/0718/c14800a267874/page.htm https://blog.csdn.net/wuwenshequ/article/details/142184860 https://stack.chaitin.com/vuldb/detail/ee958c22-c331-443e-bcda-3759dc369f8b https://www.ddpoc.com/DVB-2023-4189.html https://wx.zsxq.com/group/555848225184/topic/4844144882251418
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞泛微-Ecology10 getFieldValueFun SQL注入漏洞泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞PoCecology-execforstr-rce: Weaver Ecology ExecForStr Remote Command ExecutionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information Disclosure泛微E-ecology 10 /papi/file/module/upload SQL 注入漏洞泛微 E-Cology /hrm/hrm_e9/orgChart/js/jquery/plugins/jqueryFileTree/connectors/jqueryFileTree.jsp 目录遍历漏洞泛微ecology10 存在sql注入漏洞泛微E-Cology9 /services/WorkPlanService SQL 注入漏洞PoC泛微E-cology 10 /papi/em/transform/getEmDsList 信息泄露漏洞泛微E-cology10 dubboApi 存在远程代码执行漏洞