References https://avd.aliyun.com/detail?id=AVD-2020-22211 https://cve.imfht.com/detail/CVE-2020-22211 https://www.ddpoc.com/DVB-2023-4060.html https://github.com/advisories/GHSA-x988-8hhc-g6v9 https://pentest-tools.com/vulnerabilities-exploits/74cms-ajax-streetphp-key-sql-injection_2421 https://nvd.nist.gov/vuln/detail/CVE-2020-22211 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22211.yaml https://www.dptech.com/index.php?m=content&c=index&a=show&catid=191&id=43&type=fd2&fileurl=/uploadfile/2023/0915/20230915025529731.pdf&filename=%E8%AF%B4%E6%98%8E%E4%B9%A6_DP-FW1000-IPS-R3.1.325 https://avd.aliyun.com/product?prod=74cms
Related VulnerabilitiesCVE-2020-22208: 74cms - ajax_street.php 'x' SQL InjectionPoCCVE-2020-22209: 74cms - ajax_common.php SQL InjectionPoCCVE-2020-22210: 74cms - ajax_officebuilding.php SQL InjectionPoCCVE-2020-22211: 74cms - ajax_street.php 'key' SQL InjectionPoCCVE-2022-26271: 74cmsSE v3.4.1 - Arbitrary File ReadPoC74cms-ajax-personal-controller-class-php-sqlinject: 74 CMS 5.0.1 SQL 注入漏洞PoC74cms-sqli-1: 74 CMS SQL 注入漏洞PoC74cms-sqli-2: 74 CMS SQL 注入漏洞PoCCVE-2020-29279: 74CMS - Remote File Inclusion