Update README.md

MetaCRM 客户关系管理系统 sendfile.jsp 任意文件上传漏洞
北京时空智友ERP系统 updater.uploadStudioFile 文件上传漏洞
泛微E-cology js/hrm/getdata.jsp SQL注入漏洞
汉王e脸通智慧园区管理平台 授权激活bypass+开启JVM远程调试
用友NC uncancelEvent SQL注入漏洞
用友NC ActivityNotice/export SQL注入漏洞
通达OA OfficeTask udp 2397 端口SQL注入漏洞检测工具
通达OA OfficeTask udp 2397 端口远程代码执行RCE检测工具
宏景人力资源管理系统 HrpService 多处XXE漏洞
Unibox postprosa.php sql注入漏洞
用友NC deleteEvent SQL注入漏洞
宏景人力资源管理系统 HrpService SQL注入漏洞
宏景人力资源管理系统 DigestDownLoad SQL注入漏洞
宏景人力资源管理系统 HrChangeInfoService SQL注入漏洞+XXE漏洞
用友NC changeEvent SQL注入漏洞
用友NC /mp/view sql注入漏洞
时空智友企业流程化管控系统 getRemoteAddr 设计缺陷漏洞
用友NC oacofile/down 文件读取/删除漏洞
用友NC qrySubPurchaseOrgByParentPk SQL注入漏洞
美特CRM ws XXE漏洞
美特CRM fileUpAndDown 反序列化代码执行漏洞
美特CRM getFile 任意文件读取与反序列化漏洞
百易云资产管理运营系统 make SQL注入漏洞
用友NC loadDoc.ajax 文件读取漏洞
Western Digital My Cloud NAS multi_uploadify.php 文件上传漏洞
Western Digital My Cloud NAS chk_vv_sharename.php 命令执行漏洞
Western Digital My Cloud NAS login_checker.php 权限绕过漏洞
银达汇智智慧综合管理平台 ADTag.ashx SQL注入漏洞
Salia PLCC firmware.php 任意文件上传漏洞
This commit is contained in:
东方有鱼名为咸
2025-07-27 14:54:42 +08:00
committed by GitHub
parent 65396d4c20
commit da2288e49d
+29
View File
@@ -633,6 +633,35 @@
- [Unibox路由器 authentication/test_userlogin.php 命令执行漏洞](https://mrxn.net/jswz/unibox-authentication-test_userlogin-rce.html)
- [锐捷-EWEB cli.php 命令注入漏洞](https://mrxn.net/jswz/ruijieweb-cli-rce.html)
- [Unibox路由器 network/checkstatus_ping.php 命令执行漏洞](https://mrxn.net/jswz/unibox-network-checkstatus_ping-rce.html)
- [MetaCRM 客户关系管理系统 sendfile.jsp 任意文件上传漏洞](https://mrxn.net/jswz/metasoft-business-sendfile-upload-rce.html)
- [北京时空智友ERP系统 updater.uploadStudioFile 文件上传漏洞](https://mrxn.net/jswz/skzy-formservice-updater-uploadStudioFile.html)
- [泛微E-cology js/hrm/getdata.jsp SQL注入漏洞](https://mrxn.net/jswz/fanwei-ecology-getdata-sqli.html)
- [汉王e脸通智慧园区管理平台 授权激活bypass+开启JVM远程调试](https://mrxn.net/jswz/efacego-auth-bypass.html)
- [用友NC uncancelEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-uncancelEvent-sqli.html)
- [用友NC ActivityNotice/export SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-ActivityNotice-export-sqli.html)
- [通达OA OfficeTask udp 2397 端口SQL注入漏洞检测工具](https://mrxn.net/hacktools/tongda-OfficeTask-sqli-tools.html)
- [通达OA OfficeTask udp 2397 端口远程代码执行RCE检测工具](https://mrxn.net/hacktools/tongda-OfficeTask-RCE-tools.html)
- [宏景人力资源管理系统 HrpService 多处XXE漏洞](https://mrxn.net/jswz/hjsoft-services-HrpServices-XXE.html)
- [Unibox postprosa.php sql注入漏洞](https://mrxn.net/jswz/unibox-api-postprosa-sqli.html)
- [用友NC deleteEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-deleteEvent-sqli.html)
- [宏景人力资源管理系统 HrpService SQL注入漏洞](https://mrxn.net/jswz/hjsoft-HrpService-sqli.html)
- [宏景人力资源管理系统 DigestDownLoad SQL注入漏洞](https://mrxn.net/hjsoft-DigestDownLoad-sqli.html)
- [宏景人力资源管理系统 HrChangeInfoService SQL注入漏洞+XXE漏洞](https://mrxn.net/jswz/hjsoft-HrChangeInfoService-sqli.html)
- [用友NC changeEvent SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-oacoSchedulerEvents-changeEvent-sqli.html)
- [用友NC /mp/view sql注入漏洞](https://mrxn.net/jswz/yonyou-nc-mp-view-pageName-sqli.html)
- [时空智友企业流程化管控系统 getRemoteAddr 设计缺陷漏洞](https://mrxn.net/jswz/bjskzy-getRemoteAddr-getClientIP-xff-df.html)
- [用友NC oacofile/down 文件读取/删除漏洞](https://mrxn.net/jswz/yonyou-nc-oacofile-down-fileread-delete.html)
- [用友NC qrySubPurchaseOrgByParentPk SQL注入漏洞](https://mrxn.net/jswz/yonyou-nc-ebvp-register-qrySubPurchaseOrgByParentPk-sqli.html)
- [美特CRM ws XXE漏洞](https://mrxn.net/jswz/metasoft-services-ws-dom4j-xxe.html)
- [美特CRM fileUpAndDown 反序列化代码执行漏洞](https://mrxn.net/jswz/metasoft-fileUpAndDown-fastjson-insecure-deserialization-rce.html)
- [美特CRM getFile 任意文件读取与反序列化漏洞](https://mrxn.net/jswz/metasoft-getFile-rce-fileread.html)
- [百易云资产管理运营系统 make SQL注入漏洞](https://mrxn.net/jswz/baiyishequ-adminx-make-project_id-sqli.html)
- [用友NC loadDoc.ajax 文件读取漏洞](https://mrxn.net/jswz/yonyou-nc-uapws-loadDoc-fileread.html)
- [Western Digital My Cloud NAS multi_uploadify.php 文件上传漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-multi_uploadify-rce.html)
- [Western Digital My Cloud NAS chk_vv_sharename.php 命令执行漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-chk_vv_sharename-rce.html)
- [Western Digital My Cloud NAS login_checker.php 权限绕过漏洞](https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-login_checker-authbypass.html)
- [银达汇智智慧综合管理平台 ADTag.ashx SQL注入漏洞](https://mrxn.net/jswz/windor-Module-BPCJ-AD_Tag-Controller-ADTag-sqli.html)
- [Salia PLCC firmware.php 任意文件上传漏洞](https://mrxn.net/jswz/salia-firmware-upload-rce.html)
## <span id="head5"> 提权辅助相关</span>