References https://github.com/ibaiw/2024Hvv/blob/main/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0fl_define_flow_chart_show.aspx%20SQL%E6%B3%A8%E5%85%A5.md https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0%E5%A4%9A%E4%B8%AA%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5.md https://blog.csdn.net/qq_36618918/article/details/135485555 https://mrxn.net/jswz/landray-eis-fl_define_edit-sqli.html https://www.cnblogs.com/0neOr2eR0/p/18723789 https://cn-sec.com/archives/2544293.html https://xsx.tw/exploit/3430/ https://avd.aliyun.com/detail?id=AVD-2023-1700337 https://www.ddpoc.com/DVB-2023-5373.html
Related VulnerabilitiesPoC蓝凌EIS智慧协同平台 /common/FI_SelEmp.aspx SQL 注入漏洞蓝凌EIS智慧协同平台 /Mobile/mobile_define.aspx/Getmobiles SQL 注入漏洞PoC蓝凌-EIS智慧协同平台 /third/DingTalk/Pages/DingTalkMessage.aspx SQL 注入漏洞PoC蓝凌EIS智慧协同平台 /mail/mail_server.aspx/mail_xml XML 外部实体注入漏洞蓝凌EIS validate 存在SQL注入漏洞蓝凌EIS智慧协同平台 /Mobile/mobile_send.aspx SQL 注入漏洞PoClandray-eis-saveimg-fileupload: 蓝凌EIS智慧协同平台任意文件上传PoClandray-zhihuixietong-dingusers-sqli: 蓝凌EIS智慧协同平台DingUsers.aspx接口存在SQL注入漏洞PoClandray-eis-sqli: Landray EIS - SQL Injection蓝凌EIS智慧协同平台 /SM/DingUsers.aspx SQL 注入漏洞