References https://beaglesecurity.com/blog/vulnerability/duomicms-sql-injection.html https://nvd.nist.gov/vuln/detail/CVE-2018-18084 https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/duomicms-sql-injection.yaml https://vuldb.com/?id.125157 https://www.cve.org/CVERecord?id=CVE-2018-18084 https://github.com/cqr-cryeye-forks/goby-pocs/blob/main/DuomiCms-SQLi-(CNVD-2018-05568).json https://blog.csdn.net/xiru9972/article/details/115138374 https://mochazz.github.io/2018/09/30/DuomiCms3.0%E6%9C%80%E6%96%B0%E7%89%88%E6%BC%8F%E6%B4%9E%E6%8C%96%E6%8E%98/ https://github.com/Mochazz/Mochazz.github.io/blob/master/2018/09/30/DuomiCms3.0%E6%9C%80%E6%96%B0%E7%89%88%E6%BC%8F%E6%B4%9E%E6%8C%96%E6%8E%98/index.html
Related VulnerabilitiesPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCchanjet-crm-sqli: Chanjet CRM - SQL Injectionamtt-hiboss-language-sqli: 安美数字酒店宽带运营系统SQL注入漏洞chanjet-tplus-checkpassword-sqli: 用友 畅捷通T+ CheckPassword SQL注入漏洞ecology-ebridge-addtaste-sqli: 泛微云桥 taste/addTaste SQL注入ecology-ifnewscheckoutbycurrentuser-dwr-sqli: 泛微 E-Cology ifnewscheckoutbycurrentuser.dwr SQL 注入fangweicms-sqli: FangweiCMS sqlifeiqi-parsetree-sqli: 飞企互联-FE企业运营管理平台 parseTree 接口SQL注入finecms-sqli: FineCMS sqlifumengyun-licmanage-sqli: 孚盟云LicManage SQL注入seacms-sqli: SeaCMS sqliseeyon-wooyun-2015-0108235-sqli: seeyon wooyun 2015 0108235 sqli