References https://cn-sec.com/archives/3767453.html https://stack.chaitin.com/techblog/detail/178 https://github.com/adysec/POC/blob/main/wpoc/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E5%92%8Csql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://developer.aliyun.com/article/1376004 https://cn-sec.com/archives/3351972.html https://www.mhtsec.com/229/ https://github.com/ZXX-9527/enter_poc https://avd.aliyun.com/detail?id=AVD-2024-46088 https://cve.imfht.com/detail/CVE-2024-46088 https://www.nsfocus.net/vulndb/108351
Related Vulnerabilities浙大恩特客户资源管理系统 /entsoft/EmailMarketingAction.emrser;.js SQL 注入漏洞浙大恩特客户资源管理系统 /entsoft/T0140_editAction.entweb;.js SQL 注入漏洞PoCzheda-ente-customer-resource-management-system-fileupload: 浙大恩特客户资源管理系统任意文件上传PoCzheda-ente-entsoft-en-fileupload: 浙大恩特客户资源管理系统fileupload.jsp接口任意文件上传漏洞浙大恩特客户资源管理系统 存在默认口令浙大恩特客户资源管理系统 CompInfoAction接口存在SQL 注入漏洞浙大恩特客户资源管理系统 /entsoft/ProductAction.entphone;.js 文件上传漏洞浙大恩特客户资源管理系统 /CompInfoAction.emrser;.js SQL 注入漏洞浙大恩特客户资源管理系统 /MailAction.entphone;.js 文件上传漏洞