References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E7%B3%BB%E7%BB%9Fshow_download_content%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3135949.html https://cn-sec.com/archives/3128713.html https://blog.csdn.net/qq_34780861/article/details/137295608 https://ddpoc.com/DVB-2024-8123.html https://github.com/zan8in/wy876-POC https://s4e.io/tools/nc-cloud-sql-injection
Related Vulnerabilities畅捷通T+ERP系统Ufida.T.SM.FC.UIP接口处存在反序列化漏洞用友NC Cloud /ebvp/infopub/show_download_content;.js SQL 注入漏洞畅捷通T+ /tplus/ajaxpro/Ufida.T.SM.UIP.MultiCompanySettingController.Ufida.T.SM.UIP.ashx SQL 注入漏洞yonyou-ufida-oa-uapws-xxe: 用友 UFIDA OA XXEPoCCVE-2025-2709: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2710: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2711: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2712: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVD-2023-3118: 用友 UFIDA ActionHandlerServlet 反序列化漏洞PoCyonyou-ufida-ksoa-image-upload-file: 用友-时空KSOA ImageUpload 任意文件上传PoCCNVD-2021-30167: UFIDA NC BeanShell Remote Command ExecutionPoCCNVD-C-2023-76801: UFIDA NC uapjs - Remote Code ExecutionPoCCNVD-2024-33023: UFIDA U8 Cloud - SQL Injection