References https://peiqi.wgpsec.org/wiki/cms/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%93%2011.6%20api-getModel-api-sql-sql%20%E5%90%8E%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://zhuanlan.zhihu.com/p/621711645 http://wwlib.cn/index.php/artread/artid/9323.html https://stack.chaitin.com/poc/detail/4552 https://hackeyes.github.io/2021/04/09/%E7%A6%85%E9%81%9311.6SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E/ https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%93%2011.6%20sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E/ https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%9311.6%E5%90%8E%E5%8F%B0SQL%E6%B3%A8%E5%85%A5/ https://blog.takake.com/posts/8399/ https://www.cnblogs.com/Xor0ne/articles/13370706.html https://www.cnblogs.com/liliyuanshangcao/p/13285111.html
Related VulnerabilitiesPoCzentao-api-getmodel-api-getmethod-filepath-fileread: 禅道 11.6 Api getModel api getMethod filePath 任意文件读取漏洞禅道项目管理系统 api-getModel-file-parseCSV-fileName 参数存在任意文件读取漏洞禅道项目管理系统 /api-getModel-api-sql-sql 路径存在SQL注入