References https://github.com/Sec-Fork/POC-20240918/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9A-TPlus-CheckMutex%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/qq_40550150/article/details/137014001 http://www.sxxdckj.com/cms/a/chang-jie-tong-xin-xi-ji-shu-gu-fen-you-xian-gong-si-chang-jie-tong-T-cun-zai-SQL-zhu-ru-lou-dong-CNVD-2024-24538.html https://avd.aliyun.com/detail?id=AVD-2024-1768610 https://www.secrss.com/articles/55577 https://zhuanlan.zhihu.com/p/636981077 https://github.com/zan8in/wy876-POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ATPlus-InitServerInfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://blog.nsfocus.net/t-sql/ https://www.cnblogs.com/LeouMaster/p/18190505 https://github.com/Sweelg/QVD-2023-13612_TPlus-SQLvuln https://www.cnblogs.com/pursue-security/p/17684691.html https://avd.aliyun.com/detail?id=AVD-2024-5653
Related Vulnerabilities畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞畅捷通T+ DownLoadBlockFile 存在任意文件读取漏洞PoC畅捷通T+ /tplus/FormReport/FormReportOperateAction.aspx 文件读取漏洞用友 畅捷通T+ InitContext 登录绕过漏洞用友 畅捷通T+ SaveFileInfoToFile 任意文件上传漏洞用友 畅捷通T+ GetRecordAll 敏感信息泄露漏洞畅捷通T+ ME_MemberIntegral_IntegralAdjust 存在反序列化漏洞畅捷通T+ getdecallusers信息泄露漏洞PoCCNVD-2022-60632: 畅捷通T+ SetupAccount 任意文件上传PoCyonyou-chanjet-tplus-password-reset: 用友 畅捷通T+ RecoverPassword.aspx 管理员密码修改漏洞PoCyonyou-chanjet-tplus-read-file: 用友 畅捷通T+ DownloadProxy.aspx 任意文件读取漏洞畅捷通T+ AccountAssociationEditListController 反序列化命令执行漏洞畅捷通T+InitContext接口漏洞