mirror of
https://github.com/Mr-xn/Penetration_Testing_POC.git
synced 2026-08-17 18:00:19 +08:00
Update README.md
MetaCRM 客户关系管理系统 sendfile.jsp 任意文件上传漏洞 北京时空智友ERP系统 updater.uploadStudioFile 文件上传漏洞 泛微E-cology js/hrm/getdata.jsp SQL注入漏洞 汉王e脸通智慧园区管理平台 授权激活bypass+开启JVM远程调试 用友NC uncancelEvent SQL注入漏洞 用友NC ActivityNotice/export SQL注入漏洞 通达OA OfficeTask udp 2397 端口SQL注入漏洞检测工具 通达OA OfficeTask udp 2397 端口远程代码执行RCE检测工具 宏景人力资源管理系统 HrpService 多处XXE漏洞 Unibox postprosa.php sql注入漏洞 用友NC deleteEvent SQL注入漏洞 宏景人力资源管理系统 HrpService SQL注入漏洞 宏景人力资源管理系统 DigestDownLoad SQL注入漏洞 宏景人力资源管理系统 HrChangeInfoService SQL注入漏洞+XXE漏洞 用友NC changeEvent SQL注入漏洞 用友NC /mp/view sql注入漏洞 时空智友企业流程化管控系统 getRemoteAddr 设计缺陷漏洞 用友NC oacofile/down 文件读取/删除漏洞 用友NC qrySubPurchaseOrgByParentPk SQL注入漏洞 美特CRM ws XXE漏洞 美特CRM fileUpAndDown 反序列化代码执行漏洞 美特CRM getFile 任意文件读取与反序列化漏洞 百易云资产管理运营系统 make SQL注入漏洞 用友NC loadDoc.ajax 文件读取漏洞 Western Digital My Cloud NAS multi_uploadify.php 文件上传漏洞 Western Digital My Cloud NAS chk_vv_sharename.php 命令执行漏洞 Western Digital My Cloud NAS login_checker.php 权限绕过漏洞 银达汇智智慧综合管理平台 ADTag.ashx SQL注入漏洞 Salia PLCC firmware.php 任意文件上传漏洞
This commit is contained in:
@@ -633,6 +633,35 @@
|
||||
- [Unibox路由器 authentication/test_userlogin.php 命令执行漏洞](https://mrxn.net/jswz/unibox-authentication-test_userlogin-rce.html)
|
||||
- [锐捷-EWEB cli.php 命令注入漏洞](https://mrxn.net/jswz/ruijieweb-cli-rce.html)
|
||||
- [Unibox路由器 network/checkstatus_ping.php 命令执行漏洞](https://mrxn.net/jswz/unibox-network-checkstatus_ping-rce.html)
|
||||
- [MetaCRM 客户关系管理系统 sendfile.jsp 任意文件上传漏洞](https://mrxn.net/jswz/metasoft-business-sendfile-upload-rce.html)
|
||||
- [北京时空智友ERP系统 updater.uploadStudioFile 文件上传漏洞](https://mrxn.net/jswz/skzy-formservice-updater-uploadStudioFile.html)
|
||||
- [泛微E-cology js/hrm/getdata.jsp SQL注入漏洞](https://mrxn.net/jswz/fanwei-ecology-getdata-sqli.html)
|
||||
- [汉王e脸通智慧园区管理平台 授权激活bypass+开启JVM远程调试](https://mrxn.net/jswz/efacego-auth-bypass.html)
|
||||
- [用友NC uncancelEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-uncancelEvent-sqli.html)
|
||||
- [用友NC ActivityNotice/export SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-ActivityNotice-export-sqli.html)
|
||||
- [通达OA OfficeTask udp 2397 端口SQL注入漏洞检测工具](https://mrxn.net/hacktools/tongda-OfficeTask-sqli-tools.html)
|
||||
- [通达OA OfficeTask udp 2397 端口远程代码执行RCE检测工具](https://mrxn.net/hacktools/tongda-OfficeTask-RCE-tools.html)
|
||||
- [宏景人力资源管理系统 HrpService 多处XXE漏洞](https://mrxn.net/jswz/hjsoft-services-HrpServices-XXE.html)
|
||||
- [Unibox postprosa.php sql注入漏洞](https://mrxn.net/jswz/unibox-api-postprosa-sqli.html)
|
||||
- [用友NC deleteEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-deleteEvent-sqli.html)
|
||||
- [宏景人力资源管理系统 HrpService SQL注入漏洞](https://mrxn.net/jswz/hjsoft-HrpService-sqli.html)
|
||||
- [宏景人力资源管理系统 DigestDownLoad SQL注入漏洞](https://mrxn.net/hjsoft-DigestDownLoad-sqli.html)
|
||||
- [宏景人力资源管理系统 HrChangeInfoService SQL注入漏洞+XXE漏洞](https://mrxn.net/jswz/hjsoft-HrChangeInfoService-sqli.html)
|
||||
- [用友NC changeEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-changeEvent-sqli.html)
|
||||
- [用友NC /mp/view sql注入漏洞](https://mrxn.net/jswz/yonyou-nc-mp-view-pageName-sqli.html)
|
||||
- [时空智友企业流程化管控系统 getRemoteAddr 设计缺陷漏洞](https://mrxn.net/jswz/bjskzy-getRemoteAddr-getClientIP-xff-df.html)
|
||||
- [用友NC oacofile/down 文件读取/删除漏洞](https://mrxn.net/jswz/yonyou-nc-oacofile-down-fileread-delete.html)
|
||||
- [用友NC qrySubPurchaseOrgByParentPk SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-ebvp-register-qrySubPurchaseOrgByParentPk-sqli.html)
|
||||
- [美特CRM ws XXE漏洞](https://mrxn.net/jswz/metasoft-services-ws-dom4j-xxe.html)
|
||||
- [美特CRM fileUpAndDown 反序列化代码执行漏洞](https://mrxn.net/jswz/metasoft-fileUpAndDown-fastjson-insecure-deserialization-rce.html)
|
||||
- [美特CRM getFile 任意文件读取与反序列化漏洞](https://mrxn.net/jswz/metasoft-getFile-rce-fileread.html)
|
||||
- [百易云资产管理运营系统 make SQL注入漏洞](https://mrxn.net/jswz/baiyishequ-adminx-make-project_id-sqli.html)
|
||||
- [用友NC loadDoc.ajax 文件读取漏洞](https://mrxn.net/jswz/yonyou-nc-uapws-loadDoc-fileread.html)
|
||||
- [Western Digital My Cloud NAS multi_uploadify.php 文件上传漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-multi_uploadify-rce.html)
|
||||
- [Western Digital My Cloud NAS chk_vv_sharename.php 命令执行漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-chk_vv_sharename-rce.html)
|
||||
- [Western Digital My Cloud NAS login_checker.php 权限绕过漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-login_checker-authbypass.html)
|
||||
- [银达汇智智慧综合管理平台 ADTag.ashx SQL注入漏洞](https://mrxn.net/jswz/windor-Module-BPCJ-AD_Tag-Controller-ADTag-sqli.html)
|
||||
- [Salia PLCC firmware.php 任意文件上传漏洞](https://mrxn.net/jswz/salia-firmware-upload-rce.html)
|
||||
|
||||
|
||||
## <span id="head5"> 提权辅助相关</span>
|
||||
|
||||
Reference in New Issue
Block a user