References https://stack.chaitin.com/techblog/detail/178 https://github.com/luck-ying/Library-POC/blob/master/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0_entphone.py https://developer.aliyun.com/article/1376004 https://blog.csdn.net/qq_36334672/article/details/135823143 https://github.com/adysec/POC/blob/main/wpoc/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E5%92%8Csql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://zhuanlan.zhihu.com/p/1961836312861577773 https://blog.csdn.net/qq_44905116/article/details/137118512 https://cn-sec.com/archives/2368172.html https://www.ddpoc.com/poc/DVB-2023-5393.html https://www.ctfiot.com/144862.html https://github.com/0day404/HV-2024-POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fcrmbasicaction%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md https://blog.csdn.net/zkaqlaoniao/article/details/134831017 https://cn-sec.com/archives/3767453.html https://cn-sec.com/archives/3351972.html https://github.com/ZXX-9527/enter_poc https://cn-sec.com/archives/2221249.html https://cn-sec.com/archives/2196260.html
Related Vulnerabilities浙大恩特客户资源管理系统 /entsoft/EmailMarketingAction.emrser;.js SQL 注入漏洞浙大恩特客户资源管理系统 /entsoft/T0140_editAction.entweb;.js SQL 注入漏洞PoCentsoft-crm-customeraction-entphone-fileupload: 浙大恩特CRM/entsoft/CustomerAction.entphone;.js?method=loadFile任意文件上传PoCzheda-ente-customer-resource-management-system-fileupload: 浙大恩特客户资源管理系统任意文件上传PoCzheda-ente-entsoft-en-fileupload: 浙大恩特客户资源管理系统fileupload.jsp接口任意文件上传漏洞浙大恩特客户资源管理系统 存在默认口令浙大恩特客户资源管理系统 CompInfoAction接口存在SQL 注入漏洞浙大恩特客户资源管理系统 /entsoft/ProductAction.entphone;.js 文件上传漏洞浙大恩特客户资源管理系统 /CompInfoAction.emrser;.js SQL 注入漏洞