References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%BC%81%E6%9C%9B%E5%88%B6%E9%80%A0ERP/%E4%BC%81%E6%9C%9B%E5%88%B6%E9%80%A0ERP%E7%B3%BB%E7%BB%9FdrawGrid.action%E5%AD%98%E5%9C%A8SQL%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3391347.html https://ddpoc.com/DVB-2024-8444.html https://cn-sec.com/archives/3389785.html https://cn-sec.com/archives/3438840.html https://zhuanlan.zhihu.com/p/657269281
Related VulnerabilitiesPoCCVE-2026-55087: Etherpad 2.1.0 <= 3.0.0 - Cross-Site Scripting普华科技-PowerPMS系统未授权敏感信息泄露漏洞PoC智邦国际ERP /out/downfile.asp 文件读取漏洞云连ERP管理系统 /gateway/download!download.action 代码执行漏洞天问物业ERP系统 /HM/M_Main/HC/DataGetControl.aspx SQL 注入漏洞博格資訊管理顧問|ERP App - Use of Hard-coded Credentials时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞PoCCVE-2026-20253: Splunk Enterprise & Cloud Platform - Unrestricted File UploadTRUfusion Enterprise /trufusionPortal/getProjectList 权限绕过漏洞(CVE-2025-27223)月子会所ERP管理云平台news_add.aspx存在SQL注入漏洞月子会所ERP管理云平台GetCustomerCenterReceiveList存在SQL注入漏洞月子会所ERP管理云平台GetReciveSumReport存在SQL注入漏洞月子会所ERP管理云平台GetAllBabyInfo存在SQL注入漏洞