René's URL Explorer Experiment


Title: GitHub - pygopher/POC: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。

Open Graph Title: GitHub - pygopher/POC: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。

X Title: GitHub - pygopher/POC: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。

Description: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。 - pygopher/POC

Open Graph Description: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。 - pygopher/POC

X Description: 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。 - pygopher/POC

Opengraph URL: https://github.com/pygopher/POC

X: @github

direct link

Domain: patch-diff.githubusercontent.com

route-pattern/:user_id/:repository
route-controllerfiles
route-actiondisambiguate
fetch-noncev2:0a09d8b7-9637-4b3f-0abf-e55c8b7d78ed
current-catalog-service-hashf3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb
request-idECE0:2E8D97:9815C57:C4D4F9A:697EF3E4
html-safe-noncea13e7167aa6fd4af4a631cc370adf30d7c6816714a9185e08be50e44ceaddafc
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJFQ0UwOjJFOEQ5Nzo5ODE1QzU3OkM0RDRGOUE6Njk3RUYzRTQiLCJ2aXNpdG9yX2lkIjoiNDE5NTQ4MTM0Njc5NTA0MTc2NCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmacb96c5b65bc821801d18fb84fe210478402fdefe78b7b87b5f8aa532cac34c9fc
hovercard-subject-tagrepository:883691967
github-keyboard-shortcutsrepository,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location//
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/pygopher/POC
twitter:imagehttps://opengraph.githubassets.com/05250f62f230f6939a4701dca1e2788cf0b80820cf5259c6d5e1214030bdd0a3/pygopher/POC
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/05250f62f230f6939a4701dca1e2788cf0b80820cf5259c6d5e1214030bdd0a3/pygopher/POC
og:image:alt收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1200多个poc/exp,长期更新。 - pygopher/POC
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None60279d4097367e16897439d16d6bbe4180663db828c666eeed2656988ffe59f6
turbo-cache-controlno-preview
go-importgithub.com/pygopher/POC git https://github.com/pygopher/POC.git
octolytics-dimension-user_id54335957
octolytics-dimension-user_loginpygopher
octolytics-dimension-repository_id883691967
octolytics-dimension-repository_nwopygopher/POC
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forktrue
octolytics-dimension-repository_parent_id681546681
octolytics-dimension-repository_parent_nwodontian122/POC
octolytics-dimension-repository_network_root_id681546681
octolytics-dimension-repository_network_root_nwodontian122/POC
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release7c85641c598ad130c74f7bcc27f58575cac69551
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://patch-diff.githubusercontent.com/pygopher/POC#start-of-content
https://patch-diff.githubusercontent.com/
Sign in https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpygopher%2FPOC
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpygopher%2FPOC
Sign up https://patch-diff.githubusercontent.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=pygopher%2FPOC
Reloadhttps://patch-diff.githubusercontent.com/pygopher/POC
Reloadhttps://patch-diff.githubusercontent.com/pygopher/POC
Reloadhttps://patch-diff.githubusercontent.com/pygopher/POC
pygopher https://patch-diff.githubusercontent.com/pygopher
POChttps://patch-diff.githubusercontent.com/pygopher/POC
dontian122/POChttps://patch-diff.githubusercontent.com/dontian122/POC
Notifications https://patch-diff.githubusercontent.com/login?return_to=%2Fpygopher%2FPOC
Fork 0 https://patch-diff.githubusercontent.com/login?return_to=%2Fpygopher%2FPOC
Star 0 https://patch-diff.githubusercontent.com/login?return_to=%2Fpygopher%2FPOC
wiki.wy876.cnhttps://wiki.wy876.cn
0 stars https://patch-diff.githubusercontent.com/pygopher/POC/stargazers
1.2k forks https://patch-diff.githubusercontent.com/pygopher/POC/forks
Branches https://patch-diff.githubusercontent.com/pygopher/POC/branches
Tags https://patch-diff.githubusercontent.com/pygopher/POC/tags
Activity https://patch-diff.githubusercontent.com/pygopher/POC/activity
Star https://patch-diff.githubusercontent.com/login?return_to=%2Fpygopher%2FPOC
Notifications https://patch-diff.githubusercontent.com/login?return_to=%2Fpygopher%2FPOC
Code https://patch-diff.githubusercontent.com/pygopher/POC
Pull requests 0 https://patch-diff.githubusercontent.com/pygopher/POC/pulls
Actions https://patch-diff.githubusercontent.com/pygopher/POC/actions
Projects 0 https://patch-diff.githubusercontent.com/pygopher/POC/projects
Security 0 https://patch-diff.githubusercontent.com/pygopher/POC/security
Insights https://patch-diff.githubusercontent.com/pygopher/POC/pulse
Code https://patch-diff.githubusercontent.com/pygopher/POC
Pull requests https://patch-diff.githubusercontent.com/pygopher/POC/pulls
Actions https://patch-diff.githubusercontent.com/pygopher/POC/actions
Projects https://patch-diff.githubusercontent.com/pygopher/POC/projects
Security https://patch-diff.githubusercontent.com/pygopher/POC/security
Insights https://patch-diff.githubusercontent.com/pygopher/POC/pulse
Brancheshttps://patch-diff.githubusercontent.com/pygopher/POC/branches
Tagshttps://patch-diff.githubusercontent.com/pygopher/POC/tags
https://patch-diff.githubusercontent.com/pygopher/POC/branches
https://patch-diff.githubusercontent.com/pygopher/POC/tags
1,208 Commitshttps://patch-diff.githubusercontent.com/pygopher/POC/commits/main/
https://patch-diff.githubusercontent.com/pygopher/POC/commits/main/
1Panelhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/1Panel
1Panelhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/1Panel
AEGONhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AEGON
AEGONhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AEGON
AJ-Reporthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AJ-Report
AJ-Reporthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AJ-Report
AVCONhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AVCON
AVCONhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AVCON
Adobe ColdFusionhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Adobe%20ColdFusion
Adobe ColdFusionhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Adobe%20ColdFusion
Apachehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Apache
Apachehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Apache
Appium Desktophttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Appium%20Desktop
Appium Desktophttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Appium%20Desktop
Array VPNhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Array%20VPN
Array VPNhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Array%20VPN
Array-APVhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Array-APV
Array-APVhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Array-APV
Arubahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Aruba
Arubahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Aruba
AspCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AspCMS
AspCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/AspCMS
Atmailhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Atmail
Atmailhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Atmail
Bazarrhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Bazarr
Bazarrhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Bazarr
CRMEBhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CRMEB
CRMEBhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CRMEB
Calibrehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Calibre
Calibrehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Calibre
Check Point安全网关https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Check%20Point%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3
Check Point安全网关https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Check%20Point%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3
Chromehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Chrome
Chromehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Chrome
Ciscohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cisco
Ciscohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cisco
CloudPanelhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CloudPanel
CloudPanelhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CloudPanel
Cloudloghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cloudlog
Cloudloghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cloudlog
ClusterControlhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/ClusterControl
ClusterControlhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/ClusterControl
Cobblerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cobbler
Cobblerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Cobbler
Confluencehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Confluence
Confluencehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Confluence
Coremail邮件系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Coremail%E9%82%AE%E4%BB%B6%E7%B3%BB%E7%BB%9F
Coremail邮件系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Coremail%E9%82%AE%E4%BB%B6%E7%B3%BB%E7%BB%9F
Crafthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Craft
Crafthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Craft
CrushFTPhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CrushFTP
CrushFTPhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/CrushFTP
D-Linkhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/D-Link
D-Linkhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/D-Link
DATAGERRYhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DATAGERRY
DATAGERRYhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DATAGERRY
DCNhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DCN
DCNhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DCN
DThttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DT
DThttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DT
DataEasehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DataEase
DataEasehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DataEase
DataGearhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DataGear
DataGearhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/DataGear
Docassemblehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Docassemble
Docassemblehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Docassemble
EDUhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EDU
EDUhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EDU
ELADMINhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/ELADMIN
ELADMINhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/ELADMIN
EOVAhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EOVA
EOVAhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EOVA
EasyCVR视频管理平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0
EasyCVR视频管理平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0
EduSohohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EduSoho
EduSohohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EduSoho
Elgghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Elgg
Elgghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Elgg
Emloghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Emlog
Emloghttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Emlog
EnjoyRMIShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EnjoyRMIS
EnjoyRMIShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/EnjoyRMIS
Examhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Exam
Examhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Exam
F logic DataCube3https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/F%20logic%20DataCube3
F logic DataCube3https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/F%20logic%20DataCube3
F5-BIG-IPhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/F5-BIG-IP
F5-BIG-IPhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/F5-BIG-IP
FLIRhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/FLIR
FLIRhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/FLIR
Fastadminhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fastadmin
Fastadminhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fastadmin
Fortinethttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fortinet
Fortinethttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fortinet
Fortrahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fortra
Fortrahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Fortra
GeoServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/GeoServer
GeoServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/GeoServer
Githttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Git
Githttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Git
GitLabhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/GitLab
GitLabhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/GitLab
Gradiohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Gradio
Gradiohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Gradio
Grafanahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Grafana
Grafanahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Grafana
H3Chttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/H3C
H3Chttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/H3C
HSChttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/HSC
HSChttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/HSC
HSFhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/HSF
HSFhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/HSF
Hoverflyhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Hoverfly
Hoverflyhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Hoverfly
Hytechttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Hytec
Hytechttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Hytec
IP guard WebServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/IP%20guard%20WebServer
IP guard WebServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/IP%20guard%20WebServer
IP网络广播服务平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/IP%E7%BD%91%E7%BB%9C%E5%B9%BF%E6%92%AD%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0
IP网络广播服务平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/IP%E7%BD%91%E7%BB%9C%E5%B9%BF%E6%92%AD%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0
Imo云办公https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Imo%E4%BA%91%E5%8A%9E%E5%85%AC
Imo云办公https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Imo%E4%BA%91%E5%8A%9E%E5%85%AC
Ivantihttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Ivanti
Ivantihttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Ivanti
JEEVMS仓库管理系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JEEVMS%E4%BB%93%E5%BA%93%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F
JEEVMS仓库管理系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JEEVMS%E4%BB%93%E5%BA%93%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F
JEPaaS低代码平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0
JEPaaS低代码平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0
JFinalCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JFinalCMS
JFinalCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JFinalCMS
Janhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Jan
Janhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Jan
JeePlus低代码开发平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0
JeePlus低代码开发平台https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0
JeecgBoothttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JeecgBoot
JeecgBoothttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JeecgBoot
Jenkinshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Jenkins
Jenkinshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Jenkins
JetBrainshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JetBrains
JetBrainshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JetBrains
JieLinkhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JieLink
JieLinkhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JieLink
Joomlahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Joomla
Joomlahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Joomla
Journyxhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Journyx
Journyxhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Journyx
JumpServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JumpServer
JumpServerhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/JumpServer
KubePihttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/KubePi
KubePihttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/KubePi
Kuboardhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Kuboard
Kuboardhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Kuboard
LVS精益价值管理系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F
LVS精益价值管理系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F
Laykefu客服系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Laykefu%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F
Laykefu客服系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Laykefu%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F
Likeshophttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Likeshop
Likeshophttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Likeshop
LinkWeChathttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LinkWeChat
LinkWeChathttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LinkWeChat
Linksyshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Linksys
Linksyshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Linksys
LiveBOShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveBOS
LiveBOShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveBOS
LiveGBShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveGBS
LiveGBShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveGBS
LiveNVR流媒体服务软件https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveNVR%E6%B5%81%E5%AA%92%E4%BD%93%E6%9C%8D%E5%8A%A1%E8%BD%AF%E4%BB%B6
LiveNVR流媒体服务软件https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/LiveNVR%E6%B5%81%E5%AA%92%E4%BD%93%E6%9C%8D%E5%8A%A1%E8%BD%AF%E4%BB%B6
MRCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MRCMS
MRCMShttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MRCMS
MSServicehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MSService
MSServicehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MSService
Magentohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Magento
Magentohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Magento
MajorDoMohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MajorDoMo
MajorDoMohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MajorDoMo
MetaCRMhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MetaCRM
MetaCRMhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/MetaCRM
Metabasehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Metabase
Metabasehttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Metabase
Mingsofthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mingsoft
Mingsofthttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mingsoft
Miniohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Minio
Miniohttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Minio
Mtab书签导航程序https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mtab%E4%B9%A6%E7%AD%BE%E5%AF%BC%E8%88%AA%E7%A8%8B%E5%BA%8F
Mtab书签导航程序https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mtab%E4%B9%A6%E7%AD%BE%E5%AF%BC%E8%88%AA%E7%A8%8B%E5%BA%8F
Murahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mura
Murahttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Mura
NUUOhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/NUUO
NUUOhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/NUUO
Nacoshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Nacos
Nacoshttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Nacos
Ncast高清智能录播系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F
Ncast高清智能录播系统https://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F
NextGenhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/NextGen
NextGenhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/NextGen
Nexushttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Nexus
Nexushttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/Nexus
O2OAhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/O2OA
O2OAhttps://patch-diff.githubusercontent.com/pygopher/POC/tree/main/O2OA
READMEhttps://patch-diff.githubusercontent.com/pygopher/POC
https://patch-diff.githubusercontent.com/pygopher/POC#漏洞收集
https://patch-diff.githubusercontent.com/pygopher/POC#贡献者
https://github.com/wy876/POC/graphs/contributors
https://patch-diff.githubusercontent.com/pygopher/POC#20241102-新增漏洞
万户ezoffice协同办公平台SignatureEditFrm存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezoffice%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0SignatureEditFrm%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
禅道20.7后台任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%9320.7%E5%90%8E%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
瑞斯康达main.asp未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BE/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BEmain.asp%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
cyberpanel未授权远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/cyberpanel/cyberpanel%E6%9C%AA%E6%8E%88%E6%9D%83%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
金和OA-C6系统接口ApproveRemindSetExec.aspx存在XXE漏洞(CNVD-2024-40568)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8C/%E9%87%91%E5%92%8COA-C6%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ApproveRemindSetExec.aspx%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E(CNVD-2024-40568).md
北京亚控科技img任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%97%E4%BA%AC%E4%BA%9A%E6%8E%A7%E7%A7%91%E6%8A%80/%E5%8C%97%E4%BA%AC%E4%BA%9A%E6%8E%A7%E7%A7%91%E6%8A%80img%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
快递微信小程序系统httpRequest任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BF%AB%E9%80%92/%E5%BF%AB%E9%80%92%E5%BE%AE%E4%BF%A1%E5%B0%8F%E7%A8%8B%E5%BA%8F%E7%B3%BB%E7%BB%9FhttpRequest%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Apache-Solr身份认证绕过导致任意文件读取漏洞复现(CVE-2024-45216)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-Solr%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E5%AF%BC%E8%87%B4%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2024-45216).md
吉大正元身份认证网关downTools任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%89%E5%A4%A7%E6%AD%A3%E5%85%83%E4%BF%A1%E6%81%AF/%E5%90%89%E5%A4%A7%E6%AD%A3%E5%85%83%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BD%91%E5%85%B3downTools%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
赛普EAP企业适配管理平台Download.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E6%99%AE/%E8%B5%9B%E6%99%AEEAP%E4%BC%81%E4%B8%9A%E9%80%82%E9%85%8D%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0Download.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金华迪加现场大屏互动系统mobile.do.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%8D%8E%E8%BF%AA%E5%8A%A0/%E9%87%91%E5%8D%8E%E8%BF%AA%E5%8A%A0%E7%8E%B0%E5%9C%BA%E5%A4%A7%E5%B1%8F%E4%BA%92%E5%8A%A8%E7%B3%BB%E7%BB%9Fmobile.do.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口approveservlet存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3approveservlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口uapbd.refdef.query存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3uapbd.refdef.query%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Teaching在线教学平台getDictItemsByTable存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%8A%E6%B5%B7%E9%B8%BD%E8%9B%8B%E7%BD%91%E7%BB%9C/Teaching%E5%9C%A8%E7%BA%BF%E6%95%99%E5%AD%A6%E5%B9%B3%E5%8F%B0getDictItemsByTable%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
智慧平台SExcelExpErr.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0SExcelExpErr.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友u9系统接口TransWebService存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bu9%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3TransWebService%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20241026-新增漏洞
瑞格智慧心理服务平台NPreenSMSList.asmx存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/%E7%91%9E%E6%A0%BC%E6%99%BA%E6%85%A7%E5%BF%83%E7%90%86%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0NPreenSMSList.asmx%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金盘微信管理平台download.jsp任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E7%9B%98/%E9%87%91%E7%9B%98%E5%BE%AE%E4%BF%A1%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0download.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Grafana表达式远程代码执行(CVE-2024-9264)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Grafana/Grafana%E8%A1%A8%E8%BE%BE%E5%BC%8F%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C(CVE-2024-9264).md
明源云GetErpConfig.aspx信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%8E%E6%BA%90%E4%BA%91/%E6%98%8E%E6%BA%90%E4%BA%91GetErpConfig.aspx%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口esnserver存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3esnserver%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
分诊叫号后台系统存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%97%E4%BA%AC%E7%A5%9E%E5%B7%9E/%E5%88%86%E8%AF%8A%E5%8F%AB%E5%8F%B7%E5%90%8E%E5%8F%B0%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
百易云资产管理运营系统ufile.api.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%84%E7%AE%A1%E4%BA%91/%E7%99%BE%E6%98%93%E4%BA%91%E8%B5%84%E4%BA%A7%E7%AE%A1%E7%90%86%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9Fufile.api.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微e-Mobile移动管理平台error存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-Mobile%E7%A7%BB%E5%8A%A8%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0error%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统存在3处弱口令漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A83%E5%A4%84%E5%BC%B1%E5%8F%A3%E4%BB%A4%E6%BC%8F%E6%B4%9E.md
HCM-Cloud云端专业人力资源平台download任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%AA%E6%BD%AE%E4%BA%91/HCM-Cloud%E4%BA%91%E7%AB%AF%E4%B8%93%E4%B8%9A%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E5%B9%B3%E5%8F%B0download%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
高校人力资源管理系统ReportServer存在敏感信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/%E9%AB%98%E6%A0%A1%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FReportServer%E5%AD%98%E5%9C%A8%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
Apache-HertzBeat-SnakeYaml反序列化漏洞(CVE-2024-42323)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-HertzBeat-SnakeYaml%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E(CVE-2024-42323).md
CRMEB电商系统PublicController.php反序列化漏洞(CVE-2024-6944)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/CRMEB/CRMEB%E7%94%B5%E5%95%86%E7%B3%BB%E7%BB%9FPublicController.php%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E(CVE-2024-6944).md
锐捷校园网自助服务系统login_judge.jsf任意文件读取漏洞补丁绕过https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E6%A0%A1%E5%9B%AD%E7%BD%91%E8%87%AA%E5%8A%A9%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Flogin_judge.jsf%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%E8%A1%A5%E4%B8%81%E7%BB%95%E8%BF%87.md
天融信运维安全审计系统存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E8%9E%8D%E4%BF%A1/%E5%A4%A9%E8%9E%8D%E4%BF%A1%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
甄云SRM云平台SpEL表达式注入漏洞(XVE-2024-18301)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%8A%E6%B5%B7%E7%94%84%E4%BA%91/%E7%94%84%E4%BA%91SRM%E4%BA%91%E5%B9%B3%E5%8F%B0SpEL%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-18301).md
鸿宇多用户商城scan_list.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%B8%BF%E5%AE%87%E7%A7%91%E6%8A%80/%E9%B8%BF%E5%AE%87%E5%A4%9A%E7%94%A8%E6%88%B7%E5%95%86%E5%9F%8Escan_list.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
易宝OA-ExecuteSqlForDataSet接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA-ExecuteSqlForDataSet%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
易宝OA-ExecuteQueryNoneResult接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA-ExecuteQueryNoneResult%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
联达OA接口uploadImg.aspx任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BE%BEOA/%E8%81%94%E8%BE%BEOA%E6%8E%A5%E5%8F%A3uploadImg.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
大商创多用户商城wholesale_flow.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%8A%E6%B5%B7%E5%95%86%E5%88%9B/%E5%A4%A7%E5%95%86%E5%88%9B%E5%A4%9A%E7%94%A8%E6%88%B7%E5%95%86%E5%9F%8Ewholesale_flow.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大商创多用户商城系统ajax_dialog.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%8A%E6%B5%B7%E5%95%86%E5%88%9B/%E5%A4%A7%E5%95%86%E5%88%9B%E5%A4%9A%E7%94%A8%E6%88%B7%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9Fajax_dialog.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
NUUO网络视频录像机upload.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/NUUO/NUUO%E7%BD%91%E7%BB%9C%E8%A7%86%E9%A2%91%E5%BD%95%E5%83%8F%E6%9C%BAupload.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Smartbi修改用户密码漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Smartbi/Smartbi%E4%BF%AE%E6%94%B9%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20241019-新增漏洞
网动统一通信平台(ActiveUC)接口iactiveEnterMeeting存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%8A%A8%E7%BB%9F%E4%B8%80%E9%80%9A%E4%BF%A1%E5%B9%B3%E5%8F%B0/%E7%BD%91%E5%8A%A8%E7%BB%9F%E4%B8%80%E9%80%9A%E4%BF%A1%E5%B9%B3%E5%8F%B0(ActiveUC)%E6%8E%A5%E5%8F%A3iactiveEnterMeeting%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
浙大恩特客户资源管理系统Quotegask_editAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FQuotegask_editAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
好视通云会议upLoad2.jsp接口处存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%BD%E8%A7%86%E9%80%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AE%E7%B3%BB%E7%BB%9F/%E5%A5%BD%E8%A7%86%E9%80%9A%E4%BA%91%E4%BC%9A%E8%AE%AEupLoad2.jsp%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC系统word.docx存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9Fword.docx%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
志华软件openfile.aspx存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BF%97%E5%8D%8E%E8%BD%AF%E4%BB%B6/%E5%BF%97%E5%8D%8E%E8%BD%AF%E4%BB%B6openfile.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
大华智能云网关注册管理平台SQL注入漏洞(CNVD-2024-38747)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E8%83%BD%E4%BA%91%E7%BD%91%E5%85%B3%E6%B3%A8%E5%86%8C%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CNVD-2024-38747).md
万户ezEIP企业管理系统productlist.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezEIP%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fproductlist.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
智联云采testService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E4%BA%92%E8%81%94%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E6%99%BA%E8%81%94%E4%BA%91%E9%87%87testService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Cloudlog系统接口delete_oqrs_line未授权SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Cloudlog/Cloudlog%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3delete_oqrs_line%E6%9C%AA%E6%8E%88%E6%9D%83SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
灵当CRM系统接口wechatSession文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%81%B5%E5%BD%93CRM/%E7%81%B5%E5%BD%93CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3wechatSession%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
灵当CRM系统接口pdf.php接口处存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%81%B5%E5%BD%93CRM/%E7%81%B5%E5%BD%93CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3pdf.php%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
WordPress插件GutenKit存在任意文件上传漏洞(CVE-2024-9234)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6GutenKit%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(CVE-2024-9234).md
WordPress插件Tainacan存在前台任意文件读取漏洞(CVE-2024-7135)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6Tainacan%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-7135).md
英飞达医学WebUserLogin.asmx信息泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6%E5%BD%B1%E5%83%8F%E5%AD%98%E6%A1%A3%E4%B8%8E%E9%80%9A%E4%BF%A1%E7%B3%BB%E7%BB%9F/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6WebUserLogin.asmx%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md
公交IC卡收单管理系统信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
知识吾爱纯净版小程序系统leibiao存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8F%91%E5%8D%A1%E7%BD%91%E7%B3%BB%E7%BB%9F/%E7%9F%A5%E8%AF%86%E5%90%BE%E7%88%B1%E7%BA%AF%E5%87%80%E7%89%88%E5%B0%8F%E7%A8%8B%E5%BA%8F%E7%B3%BB%E7%BB%9Fleibiao%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
夜莺开源监控系统存在默认用户漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%9C%E8%8E%BA%E5%BC%80%E6%BA%90%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9F/%E5%A4%9C%E8%8E%BA%E5%BC%80%E6%BA%90%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E9%BB%98%E8%AE%A4%E7%94%A8%E6%88%B7%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20241013-新增漏洞
大华智慧园区综合管理平台hasSubsystem存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0hasSubsystem%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Palo-Alto-Expedition经过身份验证的命令注入(CVE-2024-9464)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PAN-OS/CVE-2024-9464.md
PAN未授权SQL注入漏洞复现(CVE-2024-9465)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PAN-OS/PAN%E6%9C%AA%E6%8E%88%E6%9D%83SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2024-9465).md
泛微E-Cology系统接口CptInstock1Ajax存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3CptInstock1Ajax%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Qualitor系统接口checkAcesso.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Qualitor/Qualitor%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3checkAcesso.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
方正畅享全媒体新闻采编系统addOrUpdateOrg存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93/%E6%96%B9%E6%AD%A3%E7%95%85%E4%BA%AB%E5%85%A8%E5%AA%92%E4%BD%93%E6%96%B0%E9%97%BB%E9%87%87%E7%BC%96%E7%B3%BB%E7%BB%9FaddOrUpdateOrg%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
同望OA系统接口tooneAssistantAttachement.jsp任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E6%9C%9BOA/%E5%90%8C%E6%9C%9BOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3tooneAssistantAttachement.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
锐明技术Mangrove系统任意用户创建漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%98%8E%E6%8A%80%E6%9C%AFCrocus%E7%B3%BB%E7%BB%9F/%E9%94%90%E6%98%8E%E6%8A%80%E6%9C%AFMangrove%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%88%9B%E5%BB%BA%E6%BC%8F%E6%B4%9E.md
迪普DPTech-VPN任意文件读取(补丁绕过)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%BF%AA%E6%99%AE/%E8%BF%AA%E6%99%AEDPTech-VPN%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96(%E8%A1%A5%E4%B8%81%E7%BB%95%E8%BF%87).md
众智OA办公系统Login存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BC%97%E6%99%BAOA/%E4%BC%97%E6%99%BAOA%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9FLogin%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
eking管理易Html5Upload接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/eking%E7%AE%A1%E7%90%86%E6%98%93/eking%E7%AE%A1%E7%90%86%E6%98%93Html5Upload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
致远OA后台表单导入任意文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%E5%90%8E%E5%8F%B0%E8%A1%A8%E5%8D%95%E5%AF%BC%E5%85%A5%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
迈普pnsr2900x系统接口DOWNLOAD_FILE任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%BF%88%E6%99%AE%E5%A4%9A%E4%B8%9A%E5%8A%A1%E8%9E%8D%E5%90%88%E7%BD%91%E5%85%B3/%E8%BF%88%E6%99%AEpnsr2900x%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3DOWNLOAD_FILE%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20241007-新增漏洞
泛微E-Mobile硬编码口令漏洞(XVE-2024-28095)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Mobile%E7%A1%AC%E7%BC%96%E7%A0%81%E5%8F%A3%E4%BB%A4%E6%BC%8F%E6%B4%9E(XVE-2024-28095).md
用友U8-CRM系统fillbacksetting.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9Ffillbacksetting.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Qualitor系统接口processVariavel.php未授权命令注入漏洞(CVE-2023-47253)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Qualitor/Qualitor%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3processVariavel.php%E6%9C%AA%E6%8E%88%E6%9D%83%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2023-47253).md
中新天达系统存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/%E4%B8%AD%E6%96%B0%E5%A4%A9%E8%BE%BE%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
孚盟云系统接口ajaxsenddingdingmessage存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AD%9A%E7%9B%9F%E4%BA%91/%E5%AD%9A%E7%9B%9F%E4%BA%91%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ajaxsenddingdingmessage%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
FLIR-AX8热成像仪applyfirmware存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/FLIR/FLIR-AX8%E7%83%AD%E6%88%90%E5%83%8F%E4%BB%AAapplyfirmware%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
FLIR-AX8热成像仪download.php存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/FLIR/FLIR-AX8%E7%83%AD%E6%88%90%E5%83%8F%E4%BB%AAdownload.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
FLIR-AX8热成像仪palette.php存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/FLIR/FLIR-AX8%E7%83%AD%E6%88%90%E5%83%8F%E4%BB%AApalette.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
FLIR-AX8热成像仪res.php存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/FLIR/FLIR-AX8%E7%83%AD%E6%88%90%E5%83%8F%E4%BB%AAres.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
万豪娱乐存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%8F%A0%E8%8F%9C/%E4%B8%87%E8%B1%AA%E5%A8%B1%E4%B9%90%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Cups-Browsed远程命令执行漏洞(CVE-2024-47177)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/cups-browsed/CVE-2024-47177.md
Spring-Framework路径遍历漏洞(CVE-2024-38816)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Spring/Spring-Framework%E8%B7%AF%E5%BE%84%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E(CVE-2024-38816).md
万户OA系统接口GeneralWeb存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3GeneralWeb%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
Zimbra远程命令执行漏洞(CVE-2024-45519)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Zimbra/CVE-2024-45519.md
pgAdmin4存在反序列化漏洞(CVE-2024-2044)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/pgAdmin/CVE-2024-2044.md
pgAdmin4敏感信息泄露漏洞(CVE-2024-9014)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/pgAdmin/CVE-2024-9014.md
CVE-2024-8190https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ivanti/CVE-2024-8190.md
CVE-2024-22024https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ivanti/CVE-2024-22024.md
微信公众号小说漫画系统前台任意文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%BC%AB%E7%94%BB%E7%B3%BB%E7%BB%9F/%E5%BE%AE%E4%BF%A1%E5%85%AC%E4%BC%97%E5%8F%B7%E5%B0%8F%E8%AF%B4%E6%BC%AB%E7%94%BB%E7%B3%BB%E7%BB%9F%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
微信公众号小说漫画系统fileupload.php存在前台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%BC%AB%E7%94%BB%E7%B3%BB%E7%BB%9F/%E5%BE%AE%E4%BF%A1%E5%85%AC%E4%BC%97%E5%8F%B7%E5%B0%8F%E8%AF%B4%E6%BC%AB%E7%94%BB%E7%B3%BB%E7%BB%9Ffileupload.php%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
金慧综合管理信息系统LoginBegin.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E6%85%A7/%E9%87%91%E6%85%A7%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9FLoginBegin.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240926-新增漏洞
DataGear数据可视化分析平台存在SpEL表达式注入漏洞(CVE-2024-37759)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/DataGear/DataGear%E6%95%B0%E6%8D%AE%E5%8F%AF%E8%A7%86%E5%8C%96%E5%88%86%E6%9E%90%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8SpEL%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-37759).md
Apache-Seata存在Hessian反序列化漏洞(CVE-2024-22399)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-Seata%E5%AD%98%E5%9C%A8Hessian%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E(CVE-2024-22399).md
金和OA系统接口SignUpload.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3SignUpload.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8+CRM系统leadconversion.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8+CRM%E7%B3%BB%E7%BB%9Fleadconversion.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
数字通云平台智慧政务setting存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%95%B0%E5%AD%97%E9%80%9AOA/%E6%95%B0%E5%AD%97%E9%80%9A%E4%BA%91%E5%B9%B3%E5%8F%B0%E6%99%BA%E6%85%A7%E6%94%BF%E5%8A%A1setting%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
EDU智慧平台PersonalDayInOutSchoolData存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/EDU%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0PersonalDayInOutSchoolData%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
EDU某智慧平台ExpDownloadService.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EDU/EDU%E6%9F%90%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0ExpDownloadService.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
百易云资产管理运营系统ticket.edit.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%84%E7%AE%A1%E4%BA%91/%E7%99%BE%E6%98%93%E4%BA%91%E8%B5%84%E4%BA%A7%E7%AE%A1%E7%90%86%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9Fticket.edit.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
灵当CRM系统接口multipleUpload.php文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%81%B5%E5%BD%93CRM/%E7%81%B5%E5%BD%93CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3multipleUpload.php%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
天融信运维安全审计系统synRequest存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E8%9E%8D%E4%BF%A1/%E5%A4%A9%E8%9E%8D%E4%BF%A1%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9FsynRequest%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友畅捷通-TPlus系统接口FileUploadHandler.ashx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9A-TPlus%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3FileUploadHandler.ashx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
微信广告任务平台存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BE%AE%E4%BF%A1%E5%B9%BF%E5%91%8A%E4%BB%BB%E5%8A%A1%E5%B9%B3%E5%8F%B0/%E5%BE%AE%E4%BF%A1%E5%B9%BF%E5%91%8A%E4%BB%BB%E5%8A%A1%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE系统接口SendFileCheckTemplateEdit.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3SendFileCheckTemplateEdit.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
东方通upload接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E6%96%B9%E9%80%9A/%E4%B8%9C%E6%96%B9%E9%80%9Aupload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
DataEase存在数据库配置信息暴露漏洞(CVE-2024-30269)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/DataEase/DataEase%E5%AD%98%E5%9C%A8%E6%95%B0%E6%8D%AE%E5%BA%93%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF%E6%9A%B4%E9%9C%B2%E6%BC%8F%E6%B4%9E(CVE-2024-30269).md
用友U8CRM系统接口setremindtoold.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3setremindtoold.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
WordPress系统插件LearnPress存在SQL注入漏洞(CVE-2024-8522)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E7%B3%BB%E7%BB%9F%E6%8F%92%E4%BB%B6LearnPress%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-8522).md
苹果IOS端IPA签名工具request_post任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%88%86%E5%8F%91%E7%AD%BE%E5%90%8D%E7%B3%BB%E7%BB%9F/%E8%8B%B9%E6%9E%9CIOS%E7%AB%AFIPA%E7%AD%BE%E5%90%8D%E5%B7%A5%E5%85%B7request_post%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
公交IC卡收单管理系统role存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Frole%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
公交IC卡收单管理系统user存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fuser%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
公交IC卡收单管理系统bus存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fbus%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
公交IC卡收单管理系统line存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fline%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
公交IC卡收单管理系统parametercard存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BA%A4IC%E5%8D%A1%E6%94%B6%E5%8D%95%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fparametercard%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
点企来客服系统存在硬编码漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%82%B9%E4%BC%81%E6%9D%A5%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F/%E7%82%B9%E4%BC%81%E6%9D%A5%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E7%A1%AC%E7%BC%96%E7%A0%81%E6%BC%8F%E6%B4%9E.md
万户OA-fileUpload.controller任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA-fileUpload.controller%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240920-新增漏洞
唯徳知识产权管理系统WSFM.asmx接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%94%AF%E5%BE%B3%E7%9F%A5%E8%AF%86%E4%BA%A7%E6%9D%83%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%94%AF%E5%BE%B3%E7%9F%A5%E8%AF%86%E4%BA%A7%E6%9D%83%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FWSFM.asmx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
唯徳知识产权管理系统DownloadFileWordTemplate接口存在文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%94%AF%E5%BE%B3%E7%9F%A5%E8%AF%86%E4%BA%A7%E6%9D%83%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%94%AF%E5%BE%B3%E7%9F%A5%E8%AF%86%E4%BA%A7%E6%9D%83%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDownloadFileWordTemplate%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
商混ERP系统接口Operater_Action.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%95%86%E6%B7%B7ERP/%E5%95%86%E6%B7%B7ERP%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3Operater_Action.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
商混ERP系统接口StockreceiveEdit.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%95%86%E6%B7%B7ERP/%E5%95%86%E6%B7%B7ERP%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3StockreceiveEdit.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
商混ERP系统接口TaskCarToQueue.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%95%86%E6%B7%B7ERP/%E5%95%86%E6%B7%B7ERP%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3TaskCarToQueue.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
广联达OA系统接口do.asmx存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3do.asmx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
广联达OA系统接口do.asmx存在任意文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3do.asmx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
thinkphp最新CVE-2024-44902反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/thinkphp/thinkphp%E6%9C%80%E6%96%B0CVE-2024-44902%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
誉龙视音频综合管理平台TimeSyn存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%AA%89%E9%BE%99%E6%95%B0%E5%AD%97/%E8%AA%89%E9%BE%99%E8%A7%86%E9%9F%B3%E9%A2%91%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0TimeSyn%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
誉龙视音频综合管理平台FindById存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%AA%89%E9%BE%99%E6%95%B0%E5%AD%97/%E8%AA%89%E9%BE%99%E8%A7%86%E9%9F%B3%E9%A2%91%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0FindById%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
魅思视频管理系统getOrderStatus存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%AD%85%E6%80%9D%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E9%AD%85%E6%80%9D%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FgetOrderStatus%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
AC集中管理平台未授权漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/AC%E9%9B%86%E4%B8%AD%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E6%9C%AA%E6%8E%88%E6%9D%83%E6%BC%8F%E6%B4%9E.md
数字通云平台智慧政务workflow存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%95%B0%E5%AD%97%E9%80%9AOA/%E6%95%B0%E5%AD%97%E9%80%9A%E4%BA%91%E5%B9%B3%E5%8F%B0%E6%99%BA%E6%85%A7%E6%94%BF%E5%8A%A1workflow%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8CRM系统接口relobjreportlist.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3relobjreportlist.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台checkDoubleUserNameForAdd存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0checkDoubleUserNameForAdd%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
地大信息-基础信息平台GetImg任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%9C%B0%E5%A4%A7%E4%BF%A1%E6%81%AF/%E5%9C%B0%E5%A4%A7%E4%BF%A1%E6%81%AF-%E5%9F%BA%E7%A1%80%E4%BF%A1%E6%81%AF%E5%B9%B3%E5%8F%B0GetImg%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微E-Mobile系统接口cdnfile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Mobile%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3cdnfile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
灵当CRM系统接口getOrderList存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%81%B5%E5%BD%93CRM/%E7%81%B5%E5%BD%93CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3getOrderList%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网御VPN安全网关存在任意文件下载漏洞(CNVD-2024-34014)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BE%A1%E6%98%9F%E4%BA%91/%E7%BD%91%E5%BE%A1VPN%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E(CNVD-2024-34014).md
Nacos未授权下载配置信息https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Nacos/Nacos%E6%9C%AA%E6%8E%88%E6%9D%83%E4%B8%8B%E8%BD%BD%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240914-新增漏洞
DCN防火墙ping.php存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/DCN/DCN%E9%98%B2%E7%81%AB%E5%A2%99ping.php%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
大华智慧园区系统updateOcx_updateCab.action存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%B3%BB%E7%BB%9FupdateOcx_updateCab.action%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
大华智慧园区系统updateOcx_updateZip.action存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%B3%BB%E7%BB%9FupdateOcx_updateZip.action%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友U8-CRM系统chkService.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9FchkService.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE系统接口filesendcheck_gd.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3filesendcheck_gd.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Hoverfly系统接口simulation任意文件读取漏洞复现(CVE-2024-45388)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Hoverfly/Hoverfly%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3simulation%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2024-45388).md
NUUO网络视频录像机css_parser.php任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/NUUO/NUUO%E7%BD%91%E7%BB%9C%E8%A7%86%E9%A2%91%E5%BD%95%E5%83%8F%E6%9C%BAcss_parser.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
百易云资产管理运营系统house.save.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%84%E7%AE%A1%E4%BA%91/%E7%99%BE%E6%98%93%E4%BA%91%E8%B5%84%E4%BA%A7%E7%AE%A1%E7%90%86%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9Fhouse.save.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E
科荣AIO系统接口UtilServlet存在代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%8D%A3AIO/%E7%A7%91%E8%8D%A3AIO%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3UtilServlet%E5%AD%98%E5%9C%A8%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
imo云办公室接口Imo_DownLoadUI.php任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Imo%E4%BA%91%E5%8A%9E%E5%85%AC/imo%E4%BA%91%E5%8A%9E%E5%85%AC%E5%AE%A4%E6%8E%A5%E5%8F%A3Imo_DownLoadUI.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
顺景ERP管理系统UploadInvtSpFile存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A1%BA%E6%99%AFERP/%E9%A1%BA%E6%99%AFERP%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FUploadInvtSpFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
某二开版海外抢单Shua单系统存在任意用户登录漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8A%A2%E5%8D%95%E5%88%B7%E5%8D%95%E7%B3%BB%E7%BB%9F/%E6%9F%90%E4%BA%8C%E5%BC%80%E7%89%88%E6%B5%B7%E5%A4%96%E6%8A%A2%E5%8D%95Shua%E5%8D%95%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.md
Array-APV应用交付系统ping_hosts存在任意命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Array-APV/Array-APV%E5%BA%94%E7%94%A8%E4%BA%A4%E4%BB%98%E7%B3%BB%E7%BB%9Fping_hosts%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
哲霖机械ERP接口DownloadInpFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%93%B2%E9%9C%96%E6%9C%BA%E6%A2%B0ERP/%E5%93%B2%E9%9C%96%E6%9C%BA%E6%A2%B0ERP%E6%8E%A5%E5%8F%A3DownloadInpFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
章管家list.htm存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%AB%A0%E7%AE%A1%E5%AE%B6-%E5%8D%B0%E7%AB%A0%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%AB%A0%E7%AE%A1%E5%AE%B6list.htm%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台conflog.inc存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0conflog.inc%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台confmanger.inc存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0confmanger.inc%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台deptactionlist存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0deptactionlist%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台myconflist.in存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0myconflist.in%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台recodemanger.inc存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0recodemanger.inc%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台recodemangerForUser.inc存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0recodemangerForUser.inc%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台syslog.inc存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0syslog.inc%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华望云会议管理平台useractionlist存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%9C%9B%E4%BA%91/%E5%8D%8E%E6%9C%9B%E4%BA%91%E4%BC%9A%E8%AE%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0useractionlist%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240908-新增漏洞
智联云采SRM2.0系统接口autologin身份认证绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E4%BA%92%E8%81%94%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E6%99%BA%E8%81%94%E4%BA%91%E9%87%87SRM2.0%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3autologin%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
众诚网上订单系统o_sa_order.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BC%97%E8%AF%9A%E8%BD%AF%E4%BB%B6/%E4%BC%97%E8%AF%9A%E7%BD%91%E4%B8%8A%E8%AE%A2%E5%8D%95%E7%B3%BB%E7%BB%9Fo_sa_order.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud系统show_download_content接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E7%B3%BB%E7%BB%9Fshow_download_content%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Jenkins-Remoting任意文件读取漏洞(CVE-2024-43044)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Jenkins/Jenkins-Remoting%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-43044).md
WordPress插件GiveWP存在反序列漏洞(CVE-2024-5932)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6GiveWP%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E(CVE-2024-5932).md
Apache-OFBiz远程代码执行漏洞(CVE-2024-45195)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-OFBiz%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-45195).md
用友U8-Cloud系统接口MultiRepChooseAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3MultiRepChooseAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口AddTaskDataRightAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3AddTaskDataRightAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
热网无线监测系统GetMenuItem存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%83%AD%E7%BD%91%E6%97%A0%E7%BA%BF%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9F/%E7%83%AD%E7%BD%91%E6%97%A0%E7%BA%BF%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9FGetMenuItem%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240902-新增漏洞
蜂信物联(FastBee)物联网平台download存在任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%9C%82%E4%BF%A1%E7%89%A9%E8%81%94/%E8%9C%82%E4%BF%A1%E7%89%A9%E8%81%94(FastBee)%E7%89%A9%E8%81%94%E7%BD%91%E5%B9%B3%E5%8F%B0download%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
紫光电子档案管理系统selectFileRemote存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%B4%AB%E5%85%89%E7%94%B5%E5%AD%90%E6%A1%A3%E6%A1%88%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E7%B4%AB%E5%85%89%E7%94%B5%E5%AD%90%E6%A1%A3%E6%A1%88%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FselectFileRemote%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
中兴ZTE-ZSR-V2系列多业务路由器存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E5%85%B4/%E4%B8%AD%E5%85%B4ZTE-ZSR-V2%E7%B3%BB%E5%88%97%E5%A4%9A%E4%B8%9A%E5%8A%A1%E8%B7%AF%E7%94%B1%E5%99%A8%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
珠海新华通软件股份有限公司云平台存在登录绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%8F%A0%E6%B5%B7%E6%96%B0%E5%8D%8E%E9%80%9A%E8%BD%AF%E4%BB%B6%E8%82%A1%E4%BB%BD%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E7%8F%A0%E6%B5%B7%E6%96%B0%E5%8D%8E%E9%80%9A%E8%BD%AF%E4%BB%B6%E8%82%A1%E4%BB%BD%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E4%BA%91%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E7%99%BB%E5%BD%95%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
Ivanti-Virtual-Traffic-Manager存在身份验证绕过漏洞(CVE-2024-7593)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ivanti/Ivanti-Virtual-Traffic-Manager%E5%AD%98%E5%9C%A8%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E(CVE-2024-7593).md
浪潮云财务系统UploadListFile存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%AA%E6%BD%AE%E4%BA%91/%E6%B5%AA%E6%BD%AE%E4%BA%91%E8%B4%A2%E5%8A%A1%E7%B3%BB%E7%BB%9FUploadListFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
金和OA-C6系统接口jQueryUploadify.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8C/%E9%87%91%E5%92%8COA-C6%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3jQueryUploadify.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口RepAddToTaskAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3RepAddToTaskAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
EOVA未授权doInit接口存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EOVA/EOVA%E6%9C%AA%E6%8E%88%E6%9D%83doInit%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
短剧影视小程序前台base64_image_content任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F%E5%89%8D%E5%8F%B0base64_image_content%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
短剧影视小程序前台juhecurl任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F%E5%89%8D%E5%8F%B0juhecurl%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
短剧影视小程序前台未授权漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F/%E7%9F%AD%E5%89%A7%E5%BD%B1%E8%A7%86%E5%B0%8F%E7%A8%8B%E5%BA%8F%E5%89%8D%E5%8F%B0%E6%9C%AA%E6%8E%88%E6%9D%83%E6%BC%8F%E6%B4%9E.md
某仿soul欲音社交系统存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A4%BE%E4%BA%A4%E7%B3%BB%E7%BB%9F/%E6%9F%90%E4%BB%BFsoul%E6%AC%B2%E9%9F%B3%E7%A4%BE%E4%BA%A4%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240828-新增漏洞
朗新天霁智能eHR人力资源管理系统GetE01ByDeptCode存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9C%97%E6%96%B0%E5%A4%A9%E9%9C%81%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%9C%97%E6%96%B0%E5%A4%A9%E9%9C%81%E6%99%BA%E8%83%BDeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetE01ByDeptCode%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
全程云OA接口UploadFile存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%A8%E7%A8%8B%E4%BA%91OA/%E5%85%A8%E7%A8%8B%E4%BA%91OA%E6%8E%A5%E5%8F%A3UploadFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E
Nacos任意文件读写漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Nacos/Nacos%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%86%99%E6%BC%8F%E6%B4%9E.md
畅捷通CRM系统newleadset.php接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%95%85%E6%8D%B7%E9%80%9ACRM%E7%B3%BB%E7%BB%9Fnewleadset.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
智能停车管理系统GetPasswayData存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetPasswayData%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
某U挖矿质押单语言系统imageupload后台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9F/%E6%9F%90U%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9Fimageupload%E5%90%8E%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
某U挖矿质押单语言系统前台未授权修改管理员密码https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9F/%E6%9F%90U%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9F%E5%89%8D%E5%8F%B0%E6%9C%AA%E6%8E%88%E6%9D%83%E4%BF%AE%E6%94%B9%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81.md
某U挖矿质押单语言系统后台phar反序列漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9F/%E6%9F%90U%E6%8C%96%E7%9F%BF%E8%B4%A8%E6%8A%BC%E5%8D%95%E8%AF%AD%E8%A8%80%E7%B3%BB%E7%BB%9F%E5%90%8E%E5%8F%B0phar%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md
SPIP-porte_plume插件存在任意PHP执行漏洞(CVE-2024-7954)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SPIP/SPIP-porte_plume%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8FPHP%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-7954).md
通天星CMSV6车载定位监控平台getAlarmAppealByGuid存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E5%AE%9A%E4%BD%8D%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0getAlarmAppealByGuid%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
同鑫eHR人力资源管理系统GetFlowDropDownListItems存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E9%91%ABeHR/%E5%90%8C%E9%91%ABeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetFlowDropDownListItems%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240824-新增漏洞
汇智ERP系统Upload.aspx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B1%87%E6%99%BAERP/%E6%B1%87%E6%99%BAERP%E7%B3%BB%E7%BB%9FUpload.aspx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
超易企业管理系统Login.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B6%85%E6%98%93%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B6%85%E6%98%93%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FLogin.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
同享人力管理管理平台SFZService.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0SFZService.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
九思OA接口WebServiceProxy存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B9%9D%E6%80%9DOA/%E4%B9%9D%E6%80%9DOA%E6%8E%A5%E5%8F%A3WebServiceProxy%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
泛微ecology9系统接口ModeDateService存在SQL漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEecology9%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ModeDateService%E5%AD%98%E5%9C%A8SQL%E6%BC%8F%E6%B4%9E.md
Oracle-JDEdwards-EnterpriseOne未授权获取管理员密码泄漏https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Oracle/Oracle-JDEdwards-EnterpriseOne%E6%9C%AA%E6%8E%88%E6%9D%83%E8%8E%B7%E5%8F%96%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81%E6%B3%84%E6%BC%8F.md
金和OA-C6协同管理平台DBModules.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA-C6%E5%8D%8F%E5%90%8C%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0DBModules.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
瑞斯康达多业务智能网关list_service_manage.php存在未授权命令注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BE/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BE%E5%A4%9A%E4%B8%9A%E5%8A%A1%E6%99%BA%E8%83%BD%E7%BD%91%E5%85%B3list_service_manage.php%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
南京星源图科技SparkShop存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%97%E4%BA%AC%E6%98%9F%E6%BA%90%E5%9B%BE%E7%A7%91%E6%8A%80/%E5%8D%97%E4%BA%AC%E6%98%9F%E6%BA%90%E5%9B%BE%E7%A7%91%E6%8A%80SparkShop%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
SeaCMS海洋影视管理系统index.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E6%B4%8Bcms/SeaCMS%E6%B5%B7%E6%B4%8B%E5%BD%B1%E8%A7%86%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Findex.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
点企来客服系统getwaitnum存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%82%B9%E4%BC%81%E6%9D%A5%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F/%E7%82%B9%E4%BC%81%E6%9D%A5%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9Fgetwaitnum%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
山石网科应用防火墙WAF未授权命令注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B1%B1%E7%9F%B3%E7%BD%91%E7%A7%91%E4%BA%91%E9%89%B4/%E5%B1%B1%E7%9F%B3%E7%BD%91%E7%A7%91%E5%BA%94%E7%94%A8%E9%98%B2%E7%81%AB%E5%A2%99WAF%E6%9C%AA%E6%8E%88%E6%9D%83%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8Cloud系统接口MeasureQResultAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3MeasureQResultAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240821-新增漏洞
JieLink+智能终端操作平台多个接口处存在敏感信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JieLink/JieLink+%E6%99%BA%E8%83%BD%E7%BB%88%E7%AB%AF%E6%93%8D%E4%BD%9C%E5%B9%B3%E5%8F%B0%E5%A4%9A%E4%B8%AA%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
正方移动信息服务管理系统oaMobile_fjUploadByType存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%AD%A3%E6%96%B9/%E6%AD%A3%E6%96%B9%E7%A7%BB%E5%8A%A8%E4%BF%A1%E6%81%AF%E6%9C%8D%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FoaMobile_fjUploadByType%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
LiveGBS任意用户密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LiveGBS/LiveGBS%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
泛微e-cology-v10远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology-v10%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
华夏ERPV3.3存在信息泄漏漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E5%A4%8FERP/%E5%8D%8E%E5%A4%8FERPV3.3%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md
奥威亚云视频平台UploadFile.aspx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%A5%E5%A8%81%E4%BA%9A%E8%A7%86%E9%A2%91%E4%BA%91%E5%B9%B3%E5%8F%B0/%E5%A5%A5%E5%A8%81%E4%BA%9A%E4%BA%91%E8%A7%86%E9%A2%91%E5%B9%B3%E5%8F%B0UploadFile.aspx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE协同管理平台receivefile_gd.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E5%8D%8F%E5%90%8C%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0receivefile_gd.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微ecology系统接口BlogService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEecology%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3BlogService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Altenergy电力系统控制软件set_timezone接口存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B5%E5%8A%9B%E7%B3%BB%E7%BB%9F%E6%8E%A7%E5%88%B6%E8%BD%AF%E4%BB%B6/Altenergy%E7%94%B5%E5%8A%9B%E7%B3%BB%E7%BB%9F%E6%8E%A7%E5%88%B6%E8%BD%AF%E4%BB%B6set_timezone%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
私有云管理平台存在登录绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%81%E6%9C%89%E4%BA%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%A7%81%E6%9C%89%E4%BA%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E7%99%BB%E5%BD%95%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
微商城系统api.php存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BE%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F/%E5%BE%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9Fapi.php%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
微商城系统goods.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BE%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F/%E5%BE%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9Fgoods.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
某业务管理系统LoginUser存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9F%90%E4%B8%9A%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%9F%90%E4%B8%9A%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FLoginUser%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240817-新增漏洞
易宝OA-BasicService.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA-BasicService.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
章管家updatePwd.htm存在任意账号密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%AB%A0%E7%AE%A1%E5%AE%B6-%E5%8D%B0%E7%AB%A0%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%AB%A0%E7%AE%A1%E5%AE%B6updatePwd.htm%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E8%B4%A6%E5%8F%B7%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
智慧校园(安校易)管理系统FileUpAd.aspx任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD(%E5%AE%89%E6%A0%A1%E6%98%93)%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD(%E5%AE%89%E6%A0%A1%E6%98%93)%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FFileUpAd.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友crm客户关系管理help.php存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bcrm%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86help.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
方天云智慧平台系统setImg.ashx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9F/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9FsetImg.ashx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
乐享智能运维管理平台getToken存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B9%90%E4%BA%AB%E6%99%BA%E8%83%BD%E8%BF%90%E7%BB%B4%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E4%B9%90%E4%BA%AB%E6%99%BA%E8%83%BD%E8%BF%90%E7%BB%B4%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0getToken%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
ZoneMinder系统sort接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ZoneMinder/ZoneMinder%E7%B3%BB%E7%BB%9Fsort%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
WookTeam轻量级的团队在线协作系统接口searchinfo存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WookTeam%E8%BD%BB%E9%87%8F%E7%BA%A7%E7%9A%84%E5%9B%A2%E9%98%9F%E5%9C%A8%E7%BA%BF%E5%8D%8F%E4%BD%9C%E7%B3%BB%E7%BB%9F/WookTeam%E8%BD%BB%E9%87%8F%E7%BA%A7%E7%9A%84%E5%9B%A2%E9%98%9F%E5%9C%A8%E7%BA%BF%E5%8D%8F%E4%BD%9C%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3searchinfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
DeDecms接口sys_verifies.php存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/dede/DeDecms%E6%8E%A5%E5%8F%A3sys_verifies.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友U8-CRM系统接口attrlist存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3attrlist%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
红海云eHR系统pc.mob存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR%E7%B3%BB%E7%BB%9Fpc.mob%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC系统FileManager接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9FFileManager%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
杭州三一谦成科技车辆监控服务平台接口platformSql存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9D%AD%E5%B7%9E%E4%B8%89%E4%B8%80%E8%B0%A6%E6%88%90%E7%A7%91%E6%8A%80%E8%BD%A6%E8%BE%86%E7%9B%91%E6%8E%A7%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0/%E6%9D%AD%E5%B7%9E%E4%B8%89%E4%B8%80%E8%B0%A6%E6%88%90%E7%A7%91%E6%8A%80%E8%BD%A6%E8%BE%86%E7%9B%91%E6%8E%A7%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0%E6%8E%A5%E5%8F%A3platformSql%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统logincontroller接口存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Flogincontroller%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统getAllUsers身份绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FgetAllUsers%E8%BA%AB%E4%BB%BD%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
用友U8-CRM系统接口reservationcomplete.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3reservationcomplete.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-CRM接口exportdictionary.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E6%8E%A5%E5%8F%A3exportdictionary.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
方正全媒体采编系统存在syn.do信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93%E9%87%87%E7%BC%96%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8syn.do%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统LogDownLoadService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FLogDownLoadService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC接口download存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3download%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
科荣AIO管理系统endTime参数存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%8D%A3AIO/%E7%A7%91%E8%8D%A3AIO%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FendTime%E5%8F%82%E6%95%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
智互联(深圳)科技有限公司SRM智联云采系统download存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E4%BA%92%E8%81%94%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E6%99%BA%E4%BA%92%E8%81%94(%E6%B7%B1%E5%9C%B3)%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8SRM%E6%99%BA%E8%81%94%E4%BA%91%E9%87%87%E7%B3%BB%E7%BB%9Fdownload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
东华医疗协同办公系统templateFile存在任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9FtemplateFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
智能停车管理系统ToLogin存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FToLogin%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
AVCON-系统管理平台download.action存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AVCON/AVCON-%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0download.action%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
AVCON-网络视频服务系统editusercommit.php存在任意用户重置密码漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AVCON/AVCON-%E7%BD%91%E7%BB%9C%E8%A7%86%E9%A2%91%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Feditusercommit.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E9%87%8D%E7%BD%AE%E5%AF%86%E7%A0%81%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240813-新增漏洞
用友U8-Cloud系统BusinessRefAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9FBusinessRefAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微e-office10系统schema_mysql.sql敏感信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office10%E7%B3%BB%E7%BB%9Fschema_mysql.sql%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
某短视频直播打赏系统任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9F%90%E7%9F%AD%E8%A7%86%E9%A2%91%E7%9B%B4%E6%92%AD%E6%89%93%E8%B5%8F%E7%B3%BB%E7%BB%9F/%E6%9F%90%E7%9F%AD%E8%A7%86%E9%A2%91%E7%9B%B4%E6%92%AD%E6%89%93%E8%B5%8F%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
某短视频直播打赏系统后台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9F%90%E7%9F%AD%E8%A7%86%E9%A2%91%E7%9B%B4%E6%92%AD%E6%89%93%E8%B5%8F%E7%B3%BB%E7%BB%9F/%E6%9F%90%E7%9F%AD%E8%A7%86%E9%A2%91%E7%9B%B4%E6%92%AD%E6%89%93%E8%B5%8F%E7%B3%BB%E7%BB%9F%E5%90%8E%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
章管家listUploadIntelligent接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%AB%A0%E7%AE%A1%E5%AE%B6-%E5%8D%B0%E7%AB%A0%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%AB%A0%E7%AE%A1%E5%AE%B6listUploadIntelligent%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
中成科信票务管理系统SeatMapHandler.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSeatMapHandler.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
中成科信票务管理系统TicketManager.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FTicketManager.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
喰星云-数字化餐饮服务系统not_finish.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9F/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Fnot_finish.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
喰星云-数字化餐饮服务系统stock.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9F/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Fstock.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
喰星云-数字化餐饮服务系统shelflife.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9F/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Fshelflife.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
安美数字酒店宽带运营系统weather.php任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%89%E7%BE%8E%E6%95%B0%E5%AD%97%E9%85%92%E5%BA%97%E5%AE%BD%E5%B8%A6%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9F/%E5%AE%89%E7%BE%8E%E6%95%B0%E5%AD%97%E9%85%92%E5%BA%97%E5%AE%BD%E5%B8%A6%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9Fweather.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统GetImportDetailJson存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetImportDetailJson%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金斗云HKMP智慧商业软件queryPrintTemplate存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E6%96%97%E4%BA%91/%E9%87%91%E6%96%97%E4%BA%91HKMP%E6%99%BA%E6%85%A7%E5%95%86%E4%B8%9A%E8%BD%AF%E4%BB%B6queryPrintTemplate%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统SecretKeyService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSecretKeyService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
润申信息科技ERP系统CommentStandardHandler.ashx接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E7%94%B3%E4%BF%A1%E6%81%AF%E7%A7%91%E6%8A%80ERP%E7%B3%BB%E7%BB%9F/%E6%B6%A6%E7%94%B3%E4%BF%A1%E6%81%AF%E7%A7%91%E6%8A%80ERP%E7%B3%BB%E7%BB%9FCommentStandardHandler.ashx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
润申信息科技ERP系统DefaultHandler.ashx接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E7%94%B3%E4%BF%A1%E6%81%AF%E7%A7%91%E6%8A%80ERP%E7%B3%BB%E7%BB%9F/%E6%B6%A6%E7%94%B3%E4%BF%A1%E6%81%AF%E7%A7%91%E6%8A%80ERP%E7%B3%BB%E7%BB%9FDefaultHandler.ashx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240810-新增漏洞
H3C-iMC智能管理中心存在远程代码执行漏洞(XVE-2024-4567)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-iMC%E6%99%BA%E8%83%BD%E7%AE%A1%E7%90%86%E4%B8%AD%E5%BF%83%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(XVE-2024-4567).md
H3C-iMC智能管理中心autoDeploy.xhtml存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-iMC%E6%99%BA%E8%83%BD%E7%AE%A1%E7%90%86%E4%B8%AD%E5%BF%83autoDeploy.xhtml%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
同享人力资源管理系统hdlUploadFile.ashx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FhdlUploadFile.ashx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统DecryptionApp存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDecryptionApp%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统docRenewApp存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FdocRenewApp%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统SecureUsbConnection存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSecureUsbConnection%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
IP网络广播服务平台upload存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/IP%E7%BD%91%E7%BB%9C%E5%B9%BF%E6%92%AD%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0/IP%E7%BD%91%E7%BB%9C%E5%B9%BF%E6%92%AD%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0upload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
ALR-F800存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/ALR-F800%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
Atmail存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Atmail/Atmail%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
ELADMIN后台管理系统存在SSRF漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ELADMIN/ELADMIN%E5%90%8E%E5%8F%B0%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E.md
JeecgBoot系统AviatorScript表达式注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeecgBoot/JeecgBoot%E7%B3%BB%E7%BB%9FAviatorScript%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Journyx存在未经身份验证的XML外部实体注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Journyx/Journyx%E5%AD%98%E5%9C%A8%E6%9C%AA%E7%BB%8F%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%9A%84XML%E5%A4%96%E9%83%A8%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5.md
Mtab书签导航程序存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Mtab%E4%B9%A6%E7%AD%BE%E5%AF%BC%E8%88%AA%E7%A8%8B%E5%BA%8F/Mtab%E4%B9%A6%E7%AD%BE%E5%AF%BC%E8%88%AA%E7%A8%8B%E5%BA%8F%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
驰骋BPM系统存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A9%B0%E9%AA%8BBPM/%E9%A9%B0%E9%AA%8BBPM%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统CDGAuthoriseTempletService1存在SQL注入漏洞(XVE-2024-19611)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FCDGAuthoriseTempletService1%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-19611).md
赛蓝企业管理系统SubmitUploadify存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSubmitUploadify%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC系统接口link存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3link%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华DSS系统group_saveGroup存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EDSS%E7%B3%BB%E7%BB%9Fgroup_saveGroup%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
H3C-SecPath下一代防火墙local_cert_delete_both存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-SecPath%E4%B8%8B%E4%B8%80%E4%BB%A3%E9%98%B2%E7%81%AB%E5%A2%99local_cert_delete_both%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
科讯一卡通管理系统DataService.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%AE%AF%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BA%91%E5%B9%B3%E5%8F%B0/%E7%A7%91%E8%AE%AF%E4%B8%80%E5%8D%A1%E9%80%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDataService.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
三汇网关管理软件debug.php远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%89%E6%B1%87%E7%BD%91%E5%85%B3%E7%AE%A1%E7%90%86%E8%BD%AF%E4%BB%B6/%E4%B8%89%E6%B1%87%E7%BD%91%E5%85%B3%E7%AE%A1%E7%90%86%E8%BD%AF%E4%BB%B6debug.php%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE系统graph_include.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E7%B3%BB%E7%BB%9Fgraph_include.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240807-新增漏洞
蓝凌EIS智慧协同平台UniformEntry.aspx存在SQL注入漏洞(XVE-2024-19181)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0UniformEntry.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-19181).md
世邦通信SPON-IP网络对讲广播系统addmediadata.php任意文件上传漏洞(XVE-2024-19281)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1SPON-IP%E7%BD%91%E7%BB%9C%E5%AF%B9%E8%AE%B2%E5%B9%BF%E6%92%AD%E7%B3%BB%E7%BB%9Faddmediadata.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(XVE-2024-19281).md
泛微云桥(e-Bridge)系统接口addResume存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE%E4%BA%91%E6%A1%A5(e-Bridge)%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3addResume%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Apache-OFBiz授权不当致代码执行漏洞(CVE-2024-38856)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-OFBiz%E6%8E%88%E6%9D%83%E4%B8%8D%E5%BD%93%E8%87%B4%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-38856).md
易捷OA协同办公软件ShowPic接口存在任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E6%8D%B7OA/%E6%98%93%E6%8D%B7OA%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E8%BD%AF%E4%BB%B6ShowPic%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
SpringBlade系统usual接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/SpringBlade%E7%B3%BB%E7%BB%9Fusual%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR系统ajaxService接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E7%B3%BB%E7%BB%9FajaxService%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
满客宝智慧食堂系统selectUserByOrgId存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%BB%A1%E5%AE%A2%E5%AE%9D%E6%99%BA%E6%85%A7%E9%A3%9F%E5%A0%82%E7%B3%BB%E7%BB%9F/%E6%BB%A1%E5%AE%A2%E5%AE%9D%E6%99%BA%E6%85%A7%E9%A3%9F%E5%A0%82%E7%B3%BB%E7%BB%9FselectUserByOrgId%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
蓝凌EKP系统dataxml.tmpl存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEKP%E7%B3%BB%E7%BB%9Fdataxml.tmpl%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
云时空社会化商业ERP系统online存在身份认证绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E6%97%B6%E7%A9%BA/%E4%BA%91%E6%97%B6%E7%A9%BA%E7%A4%BE%E4%BC%9A%E5%8C%96%E5%95%86%E4%B8%9AERP%E7%B3%BB%E7%BB%9Fonline%E5%AD%98%E5%9C%A8%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
PerkinElmer-ProcessPlus存在文件读取漏洞(CVE-2024-6911)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PerkinElmer/PerkinElmer-ProcessPlus%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-6911).md
赛蓝企业管理系统GetCssFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetCssFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Calibre任意文件读取漏洞(CVE-2024-6781)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Calibre/Calibre%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-6781).md
Calibre远程代码执行漏洞(CVE-2024-6782)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Calibre/Calibre%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-6782).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240804-新增漏洞
同享人力管理管理平台UploadHandler存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0UploadHandler%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
jeecg-boot系统接口jmLink权限绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeecgBoot/jeecg-boot%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3jmLink%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
章管家前台任意文件上传漏洞(XVE-2024-19042)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%AB%A0%E7%AE%A1%E5%AE%B6-%E5%8D%B0%E7%AB%A0%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%AB%A0%E7%AE%A1%E5%AE%B6%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(XVE-2024-19042).md
灵动业务架构平台(LiveBOS)系统UploadFile.do接口文件上传漏洞(XVE-2023-21708)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LiveBOS/%E7%81%B5%E5%8A%A8%E4%B8%9A%E5%8A%A1%E6%9E%B6%E6%9E%84%E5%B9%B3%E5%8F%B0(LiveBOS)%E7%B3%BB%E7%BB%9FUploadFile.do%E6%8E%A5%E5%8F%A3%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(XVE-2023-21708).md
灵动业务架构平台(LiveBOS)系统UploadImage接口文件上传漏洞(XVE-2024-18835)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LiveBOS/%E7%81%B5%E5%8A%A8%E4%B8%9A%E5%8A%A1%E6%9E%B6%E6%9E%84%E5%B9%B3%E5%8F%B0(LiveBOS)%E7%B3%BB%E7%BB%9FUploadImage.do%E6%8E%A5%E5%8F%A3%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(XVE-2024-18835).md
PEPM系统Cookie存在远程代码执行漏洞(XVE-2024-16919)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PEPM%E7%B3%BB%E7%BB%9F/PEPM%E7%B3%BB%E7%BB%9FCookie%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(XVE-2024-16919).md
用友NC系统complainjudge接口SQL注入漏洞(XVE-2024-19043)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9Fcomplainjudge%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-19043).md
群杰印章物联网管理平台rest密码重置漏洞(XVE-2024-18945)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BE%A4%E6%9D%B0%E5%8D%B0%E7%AB%A0%E7%89%A9%E8%81%94%E7%BD%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E7%BE%A4%E6%9D%B0%E5%8D%B0%E7%AB%A0%E7%89%A9%E8%81%94%E7%BD%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0rest%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E(XVE-2024-18945).md
网神SecGate3600未授权添加用户漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E7%A5%9E/%E7%BD%91%E7%A5%9ESecGate3600%E6%9C%AA%E6%8E%88%E6%9D%83%E6%B7%BB%E5%8A%A0%E7%94%A8%E6%88%B7%E6%BC%8F%E6%B4%9E.md
海康威视综合安防管理平台uploadAllPackage任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0uploadAllPackage%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
信呼OA系统index存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BF%A1%E5%91%BCOA/%E4%BF%A1%E5%91%BCOA%E7%B3%BB%E7%BB%9Findex%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-Cology系统接口deleteRequestInfoByXml存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3deleteRequestInfoByXml%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
通天星CMSV6车载视频监控平台SESSION伪造漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0SESSION%E4%BC%AA%E9%80%A0%E6%BC%8F%E6%B4%9E.md
小狐狸Chatgpt付费创作系统存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B0%8F%E7%8B%90%E7%8B%B8Chatgpt%E4%BB%98%E8%B4%B9%E5%88%9B%E4%BD%9C%E7%B3%BB%E7%BB%9F/%E5%B0%8F%E7%8B%90%E7%8B%B8Chatgpt%E4%BB%98%E8%B4%B9%E5%88%9B%E4%BD%9C%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240801-新增漏洞
海康威视综合安防管理平台licenseExpire存在前台远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0licenseExpire%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
北京派网软件有限公司Panabit-Panalog大数据日志审计系统sprog_upstatus.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Panalog/%E5%8C%97%E4%BA%AC%E6%B4%BE%E7%BD%91%E8%BD%AF%E4%BB%B6%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8Panabit-Panalog%E5%A4%A7%E6%95%B0%E6%8D%AE%E6%97%A5%E5%BF%97%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fsprog_upstatus.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Quicklancer系统接口listing存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Quicklancer/Quicklancer%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3listing%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
KubePi存在JWT验证绕过漏洞(CVE-2024-36111)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/KubePi/KubePi%E5%AD%98%E5%9C%A8JWT%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E(CVE-2024-36111).md
Tenda-FH1201存在命令注入漏洞(CVE-2024-41473)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Tenda/Tenda-FH1201%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-41473).md
Tenda-FH1201存在命令注入漏洞(CVE-2024-41468)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Tenda/Tenda-FH1201%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-41468).md
海康威视综合安防管理平台clusters接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0clusters%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
广联达OA系统接口ConfigService.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ConfigService.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
广联达OA系统GetSSOStamp接口存在任意用户登录https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E7%B3%BB%E7%BB%9FGetSSOStamp%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95.md
方天云智慧平台系统Upload.ashx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9F/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9FUpload.ashx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud系统queryStaffByName存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E7%B3%BB%E7%BB%9FqueryStaffByName%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud系统queryPsnInfo存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E7%B3%BB%E7%BB%9FqueryPsnInfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
契约锁电子签章平台ukeysign存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%91%E7%BA%A6%E9%94%81%E7%94%B5%E5%AD%90%E7%AD%BE%E7%AB%A0%E7%B3%BB%E7%BB%9F/%E5%A5%91%E7%BA%A6%E9%94%81%E7%94%B5%E5%AD%90%E7%AD%BE%E7%AB%A0%E5%B9%B3%E5%8F%B0ukeysign%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
AspCMS系统commentList.asp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AspCMS/AspCMS%E7%B3%BB%E7%BB%9FcommentList.asp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
满客宝智慧食堂系统downloadWebFile存在任意文件读取漏洞(XVE-2024-18926)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%BB%A1%E5%AE%A2%E5%AE%9D%E6%99%BA%E6%85%A7%E9%A3%9F%E5%A0%82%E7%B3%BB%E7%BB%9F/%E6%BB%A1%E5%AE%A2%E5%AE%9D%E6%99%BA%E6%85%A7%E9%A3%9F%E5%A0%82%E7%B3%BB%E7%BB%9FdownloadWebFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(XVE-2024-18926).md
万户ezOFFICE协同管理平台getAutoCode存在SQL注入漏洞(XVE-2024-18749)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE%E5%8D%8F%E5%90%8C%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0getAutoCode%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-18749).md
深澜计费管理系统bind-ip远程代码执行漏洞(XVE-2024-18750)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fbind-ip%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(XVE-2024-18750).md
任我行协同CRM系统UploadFile存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BB%BB%E6%88%91%E8%A1%8C/%E4%BB%BB%E6%88%91%E8%A1%8C%E5%8D%8F%E5%90%8CCRM%E7%B3%BB%E7%BB%9FUploadFile%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
方天云智慧平台系统GetCustomerLinkman存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9F/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9FGetCustomerLinkman%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友u8-cloud系统ESBInvokerServlet存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bu8-cloud%E7%B3%BB%E7%BB%9FESBInvokerServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
3C环境自动监测监控系统ReadLog文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%8E%AF%E5%A2%83%E8%87%AA%E5%8A%A8%E7%9B%91%E6%B5%8B%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9F/3C%E7%8E%AF%E5%A2%83%E8%87%AA%E5%8A%A8%E7%9B%91%E6%B5%8B%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9FReadLog%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
ClusterControl存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ClusterControl/ClusterControl%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微E-Cology系统接口ReceiveCCRequestByXml存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ReceiveCCRequestByXml%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
致远互联FE协作办公平台apprvaddNew存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94FE%E5%8D%8F%E4%BD%9C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0apprvaddNew%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统AuthToken接口存在任意账号登录漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FAuthToken%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E8%B4%A6%E5%8F%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240730-新增漏洞
RAISECOM网关设备list_base_config.php存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/RAISECOM%E7%BD%91%E5%85%B3%E8%AE%BE%E5%A4%87/RAISECOM%E7%BD%91%E5%85%B3%E8%AE%BE%E5%A4%87list_base_config.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口PreviewKPQT.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3PreviewKPQT.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口PrintZP.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3PrintZP.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口PrintZPYG.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3PrintZPYG.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口PrintZPFB.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3PrintZPFB.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口PrintZPZP.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3PrintZPZP.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA系统接口fillKP.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3fillKP.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
拓尔思TRS媒资管理系统uploadThumb存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8B%93%E5%B0%94%E6%80%9DTRS%E5%AA%92%E8%B5%84%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%8B%93%E5%B0%94%E6%80%9DTRS%E5%AA%92%E8%B5%84%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FuploadThumb%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
方天云智慧平台系统GetCompanyItem存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9F/%E6%96%B9%E5%A4%A9%E4%BA%91%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9FGetCompanyItem%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友畅捷通-TPlus系统接口ajaxpro存在ssrf漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9A-TPlus%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ajaxpro%E5%AD%98%E5%9C%A8ssrf%E6%BC%8F%E6%B4%9E.md
泛微e-cology接口HrmService前台SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology%E6%8E%A5%E5%8F%A3HrmService%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
杭州雄威餐厅数字化综合管理平台存在存在绕过认证导致任意密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9D%AD%E5%B7%9E%E9%9B%84%E5%A8%81%E9%A4%90%E5%8E%85%E6%95%B0%E5%AD%97%E5%8C%96%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E6%9D%AD%E5%B7%9E%E9%9B%84%E5%A8%81%E9%A4%90%E5%8E%85%E6%95%B0%E5%AD%97%E5%8C%96%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E5%AD%98%E5%9C%A8%E7%BB%95%E8%BF%87%E8%AE%A4%E8%AF%81%E5%AF%BC%E8%87%B4%E4%BB%BB%E6%84%8F%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
用友U9系统DoQuery接口存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU9%E7%B3%BB%E7%BB%9FDoQuery%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
泛微ecology系统setup接口存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEecology%E7%B3%BB%E7%BB%9Fsetup%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
eking管理易FileUpload接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/eking%E7%AE%A1%E7%90%86%E6%98%93/eking%E7%AE%A1%E7%90%86%E6%98%93FileUpload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
SpringBlade系统menu接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/SpringBlade%E7%B3%BB%E7%BB%9Fmenu%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
JeecgBoot反射型XSS漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeecgBoot/JeecgBoot%E5%8F%8D%E5%B0%84%E5%9E%8BXSS%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240727-新增漏洞
金和OA-C6-GeneralXmlhttpPage.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA-C6-GeneralXmlhttpPage.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
汇智ERP接口filehandle.aspx存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B1%87%E6%99%BAERP/%E6%B1%87%E6%99%BAERP%E6%8E%A5%E5%8F%A3filehandle.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统GetJSFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetJSFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统ReadTxtLog存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FReadTxtLog%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
通达OAV11.10接口login.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOAV11.10%E6%8E%A5%E5%8F%A3login.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微e-cology9接口WorkPlanService前台SQL注入漏洞(XVE-2024-18112)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology9%E6%8E%A5%E5%8F%A3WorkPlanService%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2024-18112).md
宏脉医美行业管理系统DownLoadServerFile任意文件读取下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E8%84%89%E5%8C%BB%E7%BE%8E%E8%A1%8C%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%AE%8F%E8%84%89%E5%8C%BB%E7%BE%8E%E8%A1%8C%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDownLoadServerFile%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
Sharp多功能打印机未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Sharp/Sharp%E5%A4%9A%E5%8A%9F%E8%83%BD%E6%89%93%E5%8D%B0%E6%9C%BA%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
天问物业ERP系统ContractDownLoad存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9FContractDownLoad%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金慧综合管理信息系统LoginBegin.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E6%85%A7%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9F/%E9%87%91%E6%85%A7%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9FLoginBegin.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
红海云eHR系统kgFile.mob存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR%E7%B3%BB%E7%BB%9FkgFile.mob%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
华天动力OA系统downloadWpsFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E5%A4%A9%E5%8A%A8%E5%8A%9B/%E5%8D%8E%E5%A4%A9%E5%8A%A8%E5%8A%9BOA%E7%B3%BB%E7%BB%9FdownloadWpsFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
邦永PM2项目管理平台系统ExcelIn.aspx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%82%A6%E6%B0%B8PM2%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E9%82%A6%E6%B0%B8PM2%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E7%B3%BB%E7%BB%9FExcelIn.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC系统接口UserAuthenticationServlet存在反序列化RCE漏洞(XVE-2024-18302)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3UserAuthenticationServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE%E6%BC%8F%E6%B4%9E(XVE-2024-18302).md
用友NC及U8cloud系统接口LoggingConfigServlet存在反序列化漏洞(XVE-2024-18151)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E5%8F%8AU8cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3LoggingConfigServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E(XVE-2024-18151).md
金万维-云联应用系统接入平台GNRemote.dll前台存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E4%B8%87%E7%BB%B4-%E4%BA%91%E8%81%94%E5%BA%94%E7%94%A8%E7%B3%BB%E7%BB%9F/%E9%87%91%E4%B8%87%E7%BB%B4-%E4%BA%91%E8%81%94%E5%BA%94%E7%94%A8%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%85%A5%E5%B9%B3%E5%8F%B0GNRemote.dll%E5%89%8D%E5%8F%B0%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
天问物业ERP系统OwnerVacantDownLoad存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9FOwnerVacantDownLoad%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
天问物业ERP系统VacantDiscountDownLoad存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9FVacantDiscountDownLoad%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
浪潮云财务系统xtdysrv.asmx存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%AA%E6%BD%AE%E4%BA%91/%E6%B5%AA%E6%BD%AE%E4%BA%91%E8%B4%A2%E5%8A%A1%E7%B3%BB%E7%BB%9Fxtdysrv.asmx%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
瑞斯康达-多业务智能网关-RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BE/%E7%91%9E%E6%96%AF%E5%BA%B7%E8%BE%BE-%E5%A4%9A%E4%B8%9A%E5%8A%A1%E6%99%BA%E8%83%BD%E7%BD%91%E5%85%B3-RCE.md
超级猫签名APP分发平台前台存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B6%85%E7%BA%A7%E7%8C%AB%E7%AD%BE%E5%90%8DAPP%E5%88%86%E5%8F%91%E5%B9%B3%E5%8F%B0/%E8%B6%85%E7%BA%A7%E7%8C%AB%E7%AD%BE%E5%90%8DAPP%E5%88%86%E5%8F%91%E5%B9%B3%E5%8F%B0%E5%89%8D%E5%8F%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
超级猫签名APP分发平台前台远程文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B6%85%E7%BA%A7%E7%8C%AB%E7%AD%BE%E5%90%8DAPP%E5%88%86%E5%8F%91%E5%B9%B3%E5%8F%B0/%E8%B6%85%E7%BA%A7%E7%8C%AB%E7%AD%BE%E5%90%8DAPP%E5%88%86%E5%8F%91%E5%B9%B3%E5%8F%B0%E5%89%8D%E5%8F%B0%E8%BF%9C%E7%A8%8B%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
T18-1TOTOLINK-A6000R-远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/T18-1TOTOLINK-A6000R-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240724-新增漏洞
通天星CMSV6车载视频监控平台disable存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0disable%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
创客13星零售商城系统前台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%88%9B%E5%AE%A213%E6%98%9F%E9%9B%B6%E5%94%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F/%E5%88%9B%E5%AE%A213%E6%98%9F%E9%9B%B6%E5%94%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
建文工程管理系统BusinessManger.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BB%BA%E6%96%87%E5%B7%A5%E7%A8%8B%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%BB%BA%E6%96%87%E5%B7%A5%E7%A8%8B%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FBusinessManger.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
天问物业ERP系统AreaAvatarDownLoad.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9FAreaAvatarDownLoad.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
致远OA系统constDef接口存在代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%E7%B3%BB%E7%BB%9FconstDef%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
启明星辰天玥网络安全审计系统SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%AF%E6%98%8E%E6%98%9F%E8%BE%B0/%E5%90%AF%E6%98%8E%E6%98%9F%E8%BE%B0%E5%A4%A9%E7%8E%A5%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9FSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Bazarr任意文件读取(CVE-2024-40348)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Bazarr/Bazarr%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96(CVE-2024-40348).md
浪潮云财务系统bizintegrationwebservice.asmx存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%AA%E6%BD%AE%E4%BA%91/%E6%B5%AA%E6%BD%AE%E4%BA%91%E8%B4%A2%E5%8A%A1%E7%B3%BB%E7%BB%9Fbizintegrationwebservice.asmx%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
建文工程管理系统desktop.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BB%BA%E6%96%87%E5%B7%A5%E7%A8%8B%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%BB%BA%E6%96%87%E5%B7%A5%E7%A8%8B%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdesktop.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
帆软系统ReportServer存在SQL注入漏洞导致RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B8%86%E8%BD%AF%E6%8A%A5%E8%A1%A8/%E5%B8%86%E8%BD%AF%E7%B3%BB%E7%BB%9FReportServer%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%AF%BC%E8%87%B4RCE.md
WVP视频平台(国标28181)未授权SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WVP%E8%A7%86%E9%A2%91%E5%B9%B3%E5%8F%B0/WVP%E8%A7%86%E9%A2%91%E5%B9%B3%E5%8F%B0(%E5%9B%BD%E6%A0%8728181)%E6%9C%AA%E6%8E%88%E6%9D%83SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC系统querygoodsgridbycode接口code参数存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9Fquerygoodsgridbycode%E6%8E%A5%E5%8F%A3code%E5%8F%82%E6%95%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
锐捷RG-NBS2026G-P交换机WEB管理ping.htm未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-NBS2026G-P%E4%BA%A4%E6%8D%A2%E6%9C%BAWEB%E7%AE%A1%E7%90%86ping.htm%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
华磊科技物流modifyInsurance存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E7%A3%8A%E7%A7%91%E6%8A%80%E7%89%A9%E6%B5%81/%E5%8D%8E%E7%A3%8A%E7%A7%91%E6%8A%80%E7%89%A9%E6%B5%81modifyInsurance%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
华磊科技物流getOrderTrackingNumber存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E7%A3%8A%E7%A7%91%E6%8A%80%E7%89%A9%E6%B5%81/%E5%8D%8E%E7%A3%8A%E7%A7%91%E6%8A%80%E7%89%A9%E6%B5%81getOrderTrackingNumber%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-Mobile系统接口installOperate.do存在SSRF漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Mobile%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3installOperate.do%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E.md
润乾报表dataSphereServlet接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8dataSphereServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
联软安渡系统接口queryLinklnfo存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BD%AF/%E8%81%94%E8%BD%AF%E5%AE%89%E6%B8%A1%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3queryLinklnfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
科讯一卡通管理系统get_kq_tj_today存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%AE%AF%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BA%91%E5%B9%B3%E5%8F%B0/%E7%A7%91%E8%AE%AF%E4%B8%80%E5%8D%A1%E9%80%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fget_kq_tj_today%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
科讯一卡通管理系统dormitoryHealthRanking存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%AE%AF%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BA%91%E5%B9%B3%E5%8F%B0/%E7%A7%91%E8%AE%AF%E4%B8%80%E5%8D%A1%E9%80%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FdormitoryHealthRanking%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Apache-CloudStack中的SAML身份验证漏洞(CVE-2024-41107)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-CloudStack%E4%B8%AD%E7%9A%84SAML%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E6%BC%8F%E6%B4%9E(CVE-2024-41107).md
飞讯云MyImportData前台SQL注入(XVE-2024-18113)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E8%AE%AF%E4%BA%91/%E9%A3%9E%E8%AE%AF%E4%BA%91MyImportData%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5(XVE-2024-18113).md
资管云comfileup.php前台文件上传漏洞(XVE-2024-18154)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%84%E7%AE%A1%E4%BA%91/%E8%B5%84%E7%AE%A1%E4%BA%91comfileup.php%E5%89%8D%E5%8F%B0%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(XVE-2024-18154).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240720-新增漏洞
WebLogic远程代码执行漏洞(CVE-2024-21006)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Weblogic/WebLogic%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-21006).md
广联达OA接口ArchiveWebService存在XML实体注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E6%8E%A5%E5%8F%A3ArchiveWebService%E5%AD%98%E5%9C%A8XML%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统NetSecConfigAjax接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FNetSecConfigAjax%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统NoticeAjax接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FNoticeAjax%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
云课网校系统文件上传漏洞(DVB-2024-6594)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E8%AF%BE%E7%BD%91%E6%A0%A1%E7%B3%BB%E7%BB%9F/%E4%BA%91%E8%AF%BE%E7%BD%91%E6%A0%A1%E7%B3%BB%E7%BB%9F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(DVB-2024-6594).md
全息AI网络运维平台ajax_cloud_router_config.php存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%A8%E6%81%AFAI%E7%BD%91%E7%BB%9C%E8%BF%90%E7%BB%B4%E5%B9%B3%E5%8F%B0/%E5%85%A8%E6%81%AFAI%E7%BD%91%E7%BB%9C%E8%BF%90%E7%BB%B4%E5%B9%B3%E5%8F%B0ajax_cloud_router_config.php%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
1Panel面板最新前台RCE漏洞(CVE-2024-39911)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/1Panel/1Panel%E9%9D%A2%E6%9D%BF%E6%9C%80%E6%96%B0%E5%89%8D%E5%8F%B0RCE%E6%BC%8F%E6%B4%9E(CVE-2024-39911).md
用友CRM客户关系管理系统import.php存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BCRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fimport.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
致远互联AnalyticsCloud分析云存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94AnalyticsCloud%E5%88%86%E6%9E%90%E4%BA%91%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
海洋CMS后台admin_smtp.php存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E6%B4%8Bcms/%E6%B5%B7%E6%B4%8BCMS%E5%90%8E%E5%8F%B0admin_smtp.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
DedeCMSV5.7.114后台article_template_rand.php存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/dede/DedeCMSV5.7.114%E5%90%8E%E5%8F%B0article_template_rand.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
DedeCMSV5.7.114后台sys_verizes.php存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/dede/DedeCMSV5.7.114%E5%90%8E%E5%8F%B0sys_verizes.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
fogproject系统接口export.php存在远程命令执行漏洞(CVE-2024-39914)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/fogproject/fogproject%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3export.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-39914).md
LiveNVR流媒体服务软件接口存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LiveNVR%E6%B5%81%E5%AA%92%E4%BD%93%E6%9C%8D%E5%8A%A1%E8%BD%AF%E4%BB%B6/LiveNVR%E6%B5%81%E5%AA%92%E4%BD%93%E6%9C%8D%E5%8A%A1%E8%BD%AF%E4%BB%B6%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
拼团零售商城系统前台任意文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8B%BC%E5%9B%A2%E9%9B%B6%E5%94%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F/%E6%8B%BC%E5%9B%A2%E9%9B%B6%E5%94%AE%E5%95%86%E5%9F%8E%E7%B3%BB%E7%BB%9F%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240717-新增漏洞
Nacos远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Nacos/Nacos%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
蓝凌KEP前台RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CKEP%E5%89%8D%E5%8F%B0RCE%E6%BC%8F%E6%B4%9E.md
某自动发卡网alipay_notify.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8F%91%E5%8D%A1%E7%BD%91%E7%B3%BB%E7%BB%9F/%E6%9F%90%E8%87%AA%E5%8A%A8%E5%8F%91%E5%8D%A1%E7%BD%91alipay_notify.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统GetExcellTemperature存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetExcellTemperature%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
SuiteCRM系统接口responseEntryPoint存在SQL注入漏洞(CVE-2024-36412)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SuiteCRM/SuiteCRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3responseEntryPoint%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-36412).md
Netgear-WN604接口downloadFile.php信息泄露漏洞(CVE-2024-6646)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/Netgear-WN604%E6%8E%A5%E5%8F%A3downloadFile.php%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E(CVE-2024-6646).md
泛微e-cology9接口XmlRpcServlet存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology9%E6%8E%A5%E5%8F%A3XmlRpcServlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微E-office-10接口leave_record.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-office-10%E6%8E%A5%E5%8F%A3leave_record.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友GRP-A-Cloud政府财务云系统接口selectGlaDatasourcePreview存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-A-Cloud%E6%94%BF%E5%BA%9C%E8%B4%A2%E5%8A%A1%E4%BA%91%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3selectGlaDatasourcePreview%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud文件服务器用户登陆绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E6%96%87%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%94%A8%E6%88%B7%E7%99%BB%E9%99%86%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240714-新增漏洞
新中新中小学智慧校园信息管理系统Upload接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B0%E4%B8%AD%E6%96%B0%E4%B8%AD%E5%B0%8F%E5%AD%A6%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%96%B0%E4%B8%AD%E6%96%B0%E4%B8%AD%E5%B0%8F%E5%AD%A6%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FUpload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
金斗云-HKMP智慧商业软件download任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E6%96%97%E4%BA%91/%E9%87%91%E6%96%97%E4%BA%91-HKMP%E6%99%BA%E6%85%A7%E5%95%86%E4%B8%9A%E8%BD%AF%E4%BB%B6download%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
公众号无限回调系统接口siteUrl存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AC%E4%BC%97%E5%8F%B7%E6%97%A0%E9%99%90%E5%9B%9E%E8%B0%83%E7%B3%BB%E7%BB%9F/%E5%85%AC%E4%BC%97%E5%8F%B7%E6%97%A0%E9%99%90%E5%9B%9E%E8%B0%83%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3siteUrl%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统接口MeasQueryConditionFrameAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3MeasQueryConditionFrameAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
ServiceNow-UI存在Jelly模板注入漏洞(CVE-2024-4879)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ServiceNow%20UI/ServiceNow-UI%E5%AD%98%E5%9C%A8Jelly%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-4879).md
天喻软件数据安全平台DownLoad.ashx存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E5%96%BB%E8%BD%AF%E4%BB%B6%E6%95%B0%E6%8D%AE%E5%AE%89%E5%85%A8%E5%B9%B3%E5%8F%B0/%E5%A4%A9%E5%96%BB%E8%BD%AF%E4%BB%B6%E6%95%B0%E6%8D%AE%E5%AE%89%E5%85%A8%E5%B9%B3%E5%8F%B0DownLoad.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
启明星辰-天清汉马VPN接口download任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%AF%E6%98%8E%E6%98%9F%E8%BE%B0/%E5%90%AF%E6%98%8E%E6%98%9F%E8%BE%B0-%E5%A4%A9%E6%B8%85%E6%B1%89%E9%A9%ACVPN%E6%8E%A5%E5%8F%A3download%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
泛微OA-E-Cology接口WorkflowServiceXml存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Cology%E6%8E%A5%E5%8F%A3WorkflowServiceXml%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
全行业小程序运营系统接口Wxapps.php存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%A8%E8%A1%8C%E4%B8%9A%E5%B0%8F%E7%A8%8B%E5%BA%8F%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9F/%E5%85%A8%E8%A1%8C%E4%B8%9A%E5%B0%8F%E7%A8%8B%E5%BA%8F%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3Wxapps.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240712-新增漏洞
泛微E-Cology接口getFileViewUrl存在SSRF漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology%E6%8E%A5%E5%8F%A3getFileViewUrl%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E.md
Pyspider-WebUI未授权访问致远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Pyspider%20WebUI/Pyspider-WebUI%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E8%87%B4%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
赛蓝企业管理系统DownloadBuilder任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%B5%9B%E8%93%9D%E4%BC%81%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDownloadBuilder%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
上讯信息技术股份有限公司运维管理系统RepeatSend存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%8A%E8%AE%AF%E4%BF%A1%E6%81%AF%E6%8A%80%E6%9C%AF%E8%82%A1%E4%BB%BD%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E4%B8%8A%E8%AE%AF%E4%BF%A1%E6%81%AF%E6%8A%80%E6%9C%AF%E8%82%A1%E4%BB%BD%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E8%BF%90%E7%BB%B4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FRepeatSend%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
同享人力管理管理平台DownloadFile存在任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E5%90%8C%E4%BA%AB%E4%BA%BA%E5%8A%9B%E7%AE%A1%E7%90%86%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0DownloadFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
北京中科聚网一体化运营平台importVisualModuleImg接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%97%E4%BA%AC%E4%B8%AD%E7%A7%91%E8%81%9A%E7%BD%91/%E5%8C%97%E4%BA%AC%E4%B8%AD%E7%A7%91%E8%81%9A%E7%BD%91%E4%B8%80%E4%BD%93%E5%8C%96%E8%BF%90%E8%90%A5%E5%B9%B3%E5%8F%B0importVisualModuleImg%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud接口blobRefClassSearch存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%E6%8E%A5%E5%8F%A3blobRefClassSearch%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
慧学教育科技有限公司Campuswit_uploadFiles存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%85%A7%E5%AD%A6%E6%95%99%E8%82%B2%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E6%85%A7%E5%AD%A6%E6%95%99%E8%82%B2%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8Campuswit_uploadFiles%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
虚拟仿真实验室系统FileUploadServlet存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%99%9A%E6%8B%9F%E4%BB%BF%E7%9C%9F%E5%AE%9E%E9%AA%8C%E5%AE%A4%E7%B3%BB%E7%BB%9F/%E8%99%9A%E6%8B%9F%E4%BB%BF%E7%9C%9F%E5%AE%9E%E9%AA%8C%E5%AE%A4%E7%B3%BB%E7%BB%9FFileUploadServlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
风速科技统一认证平台存在密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%8E%E9%80%9F%E7%A7%91%E6%8A%80%E7%BB%9F%E4%B8%80%E8%AE%A4%E8%AF%81%E5%B9%B3%E5%8F%B0/%E9%A3%8E%E9%80%9F%E7%A7%91%E6%8A%80%E7%BB%9F%E4%B8%80%E8%AE%A4%E8%AF%81%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
联奕统一身份认证平台getDataSource存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E5%A5%95%E7%BB%9F%E4%B8%80%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E5%B9%B3%E5%8F%B0/%E8%81%94%E5%A5%95%E7%BB%9F%E4%B8%80%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E5%B9%B3%E5%8F%B0getDataSource%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
PowerCreator接口UploadResourcePic.ashx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PowerCreator/PowerCreator%E6%8E%A5%E5%8F%A3UploadResourcePic.ashx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
数字通OA-智慧政务接口payslip存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%95%B0%E5%AD%97%E9%80%9AOA/%E6%95%B0%E5%AD%97%E9%80%9AOA-%E6%99%BA%E6%85%A7%E6%94%BF%E5%8A%A1%E6%8E%A5%E5%8F%A3payslip%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240709-新增漏洞
申瓯通信在线录音管理系统Thinkphp远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B3%E7%93%AF%E9%80%9A%E4%BF%A1%E5%9C%A8%E7%BA%BF%E5%BD%95%E9%9F%B3%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E7%94%B3%E7%93%AF%E9%80%9A%E4%BF%A1%E5%9C%A8%E7%BA%BF%E5%BD%95%E9%9F%B3%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FThinkphp%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
EduSoho教培系统classropm-course-statistics存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EduSoho/EduSoho%E6%95%99%E5%9F%B9%E7%B3%BB%E7%BB%9Fclassropm-course-statistics%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
深澜计费管理系统proxy存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fproxy%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
深澜计费管理系统strategy存在反序列化RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B7%B1%E6%BE%9C%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fstrategy%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE%E6%BC%8F%E6%B4%9E.md
大唐电信NVS3000综合视频监控平台getDepResList存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1NVS3000%E7%BB%BC%E5%90%88%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0getDepResList%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大唐电信AC集中管理平台敏感信息泄漏漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1AC%E9%9B%86%E4%B8%AD%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md
大唐电信NVS3000综合视频监控平台getencoderlist存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1/%E5%A4%A7%E5%94%90%E7%94%B5%E4%BF%A1NVS3000%E7%BB%BC%E5%90%88%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0getencoderlist%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
厦门四信通信科技有限公司视频监控管理系统存在逻辑缺陷漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8E%A6%E9%97%A8%E5%9B%9B%E4%BF%A1%E9%80%9A%E4%BF%A1%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E5%8E%A6%E9%97%A8%E5%9B%9B%E4%BF%A1%E9%80%9A%E4%BF%A1%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E9%80%BB%E8%BE%91%E7%BC%BA%E9%99%B7%E6%BC%8F%E6%B4%9E.md
中科智远科技-综合监管云平台DownFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E7%A7%91%E6%99%BA%E8%BF%9C%E7%A7%91%E6%8A%80%E7%BB%BC%E5%90%88%E7%9B%91%E7%AE%A1%E4%BA%91%E5%B9%B3%E5%8F%B0/%E4%B8%AD%E7%A7%91%E6%99%BA%E8%BF%9C%E7%A7%91%E6%8A%80-%E7%BB%BC%E5%90%88%E7%9B%91%E7%AE%A1%E4%BA%91%E5%B9%B3%E5%8F%B0DownFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
亿华人力资源管理系统unloadfile存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E5%8D%8E%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E5%8D%8E%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Funloadfile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
EnjoyRMIS-GetOAById存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EnjoyRMIS/EnjoyRMIS-GetOAById%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿渡留言管理系统uploadimg存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E6%B8%A1%E7%95%99%E8%A8%80%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E6%B8%A1%E7%95%99%E8%A8%80%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fuploadimg%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
宏脉医美行业管理系统UEditor编辑器存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E8%84%89%E5%8C%BB%E7%BE%8E%E8%A1%8C%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%AE%8F%E8%84%89%E5%8C%BB%E7%BE%8E%E8%A1%8C%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FUEditor%E7%BC%96%E8%BE%91%E5%99%A8%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Exam在线考试系统存在前台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Exam/Exam%E5%9C%A8%E7%BA%BF%E8%80%83%E8%AF%95%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
彩票系统存在任意文件preview.php上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%8F%A0%E8%8F%9C/%E5%BD%A9%E7%A5%A8%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6preview.php%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
会捷通云视讯平台fileDownload存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BC%9A%E6%8D%B7%E9%80%9A%E4%BA%91%E8%A7%86%E8%AE%AF%E5%B9%B3%E5%8F%B0/%E4%BC%9A%E6%8D%B7%E9%80%9A%E4%BA%91%E8%A7%86%E8%AE%AF%E5%B9%B3%E5%8F%B0fileDownload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
正方数字化校园平台RzptManage存在任意文件写入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%AD%A3%E6%96%B9/%E6%AD%A3%E6%96%B9%E6%95%B0%E5%AD%97%E5%8C%96%E6%A0%A1%E5%9B%AD%E5%B9%B3%E5%8F%B0RzptManage%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md
鲸发卡系统自动发卡网request_post存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8F%91%E5%8D%A1%E7%BD%91%E7%B3%BB%E7%BB%9F/%E9%B2%B8%E5%8F%91%E5%8D%A1%E7%B3%BB%E7%BB%9F%E8%87%AA%E5%8A%A8%E5%8F%91%E5%8D%A1%E7%BD%91request_post%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友时空KSOA接口com.sksoft.bill.QueryService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E6%8E%A5%E5%8F%A3com.sksoft.bill.QueryService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240706-新增漏洞
宏景eHR人力资源管理系统接口getSdutyTree存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3getSdutyTree%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR人力资源管理系统接口loadtree存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3loadtree%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR人力资源管理系统接口LoadOtherTreeServlet存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3LoadOtherTreeServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR人力资源管理系统接口DownLoadCourseware存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3DownLoadCourseware%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
平升电子水库监管平台GetAllRechargeRecordsBySIMCardId接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%B3%E5%8D%87%E7%94%B5%E5%AD%90%E6%B0%B4%E5%BA%93%E7%9B%91%E7%AE%A1%E5%B9%B3%E5%8F%B0/%E5%B9%B3%E5%8D%87%E7%94%B5%E5%AD%90%E6%B0%B4%E5%BA%93%E7%9B%91%E7%AE%A1%E5%B9%B3%E5%8F%B0GetAllRechargeRecordsBySIMCardId%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Docassemble任意文件读取漏洞(CVE-2024-27292) https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Docassemble/Docassemble%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-27292).md
WordPress插件Recall存在SQL注入漏洞(CVE-2024-32709)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6Recall%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-32709).md
rejetto-HFS-3存在远程命令执行漏洞(CVE-2024-39943)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/HSF/rejetto-HFS-3%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-39943).md
Splunk-Enterprise任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Splunk%20Enterprise/Splunk-Enterprise%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240703-新增漏洞
金和OA_C6_UploadFileDownLoadnew存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_C6_UploadFileDownLoadnew%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
科荣AIO-moffice接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%8D%A3AIO/%E7%A7%91%E8%8D%A3AIO-moffice%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
朗新天霁人力资源管理系统GetMessage存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9C%97%E6%96%B0%E5%A4%A9%E9%9C%81%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%9C%97%E6%96%B0%E5%A4%A9%E9%9C%81%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetMessage%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友u9系统接口GetConnectionString存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bu9%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3GetConnectionString%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
YzmCMS接口存在pay_callback远程命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/YzmCMS/YzmCMS%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8pay_callback%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
美特CRM系统接口anotherValue存在FastJson反序列化RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BE%8E%E7%89%B9CRM%E7%B3%BB%E7%BB%9F/%E7%BE%8E%E7%89%B9CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3anotherValue%E5%AD%98%E5%9C%A8FastJson%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE.md
飞企互联FE企业运营管理平台ajax_codewidget39.jsp接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0ajax_codewidget39.jsp%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
飞企互联FE企业运营管理平台checkGroupCode.js接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0checkGroupCode.js%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华ICC智能物联综合管理平台heapdump敏感信息泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EICC%E6%99%BA%E8%83%BD%E7%89%A9%E8%81%94%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0heapdump%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md
英飞达医学影像存档与通信系统Upload.asmx任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6%E5%BD%B1%E5%83%8F%E5%AD%98%E6%A1%A3%E4%B8%8E%E9%80%9A%E4%BF%A1%E7%B3%BB%E7%BB%9F/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6%E5%BD%B1%E5%83%8F%E5%AD%98%E6%A1%A3%E4%B8%8E%E9%80%9A%E4%BF%A1%E7%B3%BB%E7%BB%9FUpload.asmx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
GeoServer属性名表达式前台代码执行漏洞(CVE-2024-36401)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/GeoServer/GeoServer%E5%B1%9E%E6%80%A7%E5%90%8D%E8%A1%A8%E8%BE%BE%E5%BC%8F%E5%89%8D%E5%8F%B0%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-36401).md
D-LINK-Go-RT-AC750 GORTAC750_A1_FW_v101b03存在硬编码漏洞(CVE-2024-22853)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-LINK-Go-RT-AC750%20GORTAC750_A1_FW_v101b03%E5%AD%98%E5%9C%A8%E7%A1%AC%E7%BC%96%E7%A0%81%E6%BC%8F%E6%B4%9E(CVE-2024-22853).md
致远OA-A8-V5接口officeservlet存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA-A8-V5%E6%8E%A5%E5%8F%A3officeservlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
JieLink+智能终端操作平台存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JieLink/JieLink+%E6%99%BA%E8%83%BD%E7%BB%88%E7%AB%AF%E6%93%8D%E4%BD%9C%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金斗云-HKMP智慧商业软件任意用户添加漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E6%96%97%E4%BA%91/%E9%87%91%E6%96%97%E4%BA%91-HKMP%E6%99%BA%E6%85%A7%E5%95%86%E4%B8%9A%E8%BD%AF%E4%BB%B6%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md
热网无线监测系统SystemManager.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%83%AD%E7%BD%91%E6%97%A0%E7%BA%BF%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9F/%E7%83%AD%E7%BD%91%E6%97%A0%E7%BA%BF%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9FSystemManager.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
喰星云-数字化餐饮服务系统listuser信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9F/%E5%96%B0%E6%98%9F%E4%BA%91-%E6%95%B0%E5%AD%97%E5%8C%96%E9%A4%90%E9%A5%AE%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Flistuser%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
邦永PM2项目管理系统Global_UserLogin.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%82%A6%E6%B0%B8PM2%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E9%82%A6%E6%B0%B8PM2%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGlobal_UserLogin.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
锐明技术Crocus系统Service.do任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%98%8E%E6%8A%80%E6%9C%AFCrocus%E7%B3%BB%E7%BB%9F/%E9%94%90%E6%98%8E%E6%8A%80%E6%9C%AFCrocus%E7%B3%BB%E7%BB%9FService.do%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240628-新增漏洞
WordPress插件Dokan-Pro存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6Dokan-Pro%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
时空智友ERP系统updater.uploadStudioFile接口处存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E6%97%B6%E7%A9%BA/%E6%97%B6%E7%A9%BA%E6%99%BA%E5%8F%8BERP%E7%B3%BB%E7%BB%9Fupdater.uploadStudioFile%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Apache-ServiceComb存在SSRF漏洞(CVE-2023-44313)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-ServiceComb%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E(CVE-2023-44313).md
通天星CMSV6接口pointManage存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E6%8E%A5%E5%8F%A3pointManage%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
用友U8-Cloud-smartweb2.showRPCLoadingTip.d存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud-smartweb2.showRPCLoadingTip.d%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
WordPress-MasterStudy-LMS插件存在SQL注入漏洞(CVE-2024-1512)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-MasterStudy-LMS%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-1512).md
Apache-Kafka的UI中的远程代码执行CVE-2023-52251https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-Kafka%E7%9A%84UI%E4%B8%AD%E7%9A%84%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8CCVE-2023-52251.md
碧海威L7产品confirm存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A2%A7%E6%B5%B7%E5%A8%81/%E7%A2%A7%E6%B5%B7%E5%A8%81L7%E4%BA%A7%E5%93%81confirm%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
万户-ezOFFICE-OA-officeserver.jsp文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7-ezOFFICE-OA-officeserver.jsp%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
医药信息管理系统GetLshByTj存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%BB%E8%8D%AF%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%8C%BB%E8%8D%AF%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetLshByTj%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
MSService服务init.do接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/MSService/MSService%E6%9C%8D%E5%8A%A1init.do%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Pear-Admin-Boot存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Pear%20Admin%20Boot/Pear-Admin-Boot%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
福建科立讯通信有限公司指挥调度管理平台uploadgps.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E6%8C%87%E6%8C%A5%E8%B0%83%E5%BA%A6%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0uploadgps.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Magento开源电子商务平台接口estimate-shipping-methods存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Magento/Magento%E5%BC%80%E6%BA%90%E7%94%B5%E5%AD%90%E5%95%86%E5%8A%A1%E5%B9%B3%E5%8F%B0%E6%8E%A5%E5%8F%A3estimate-shipping-methods%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
铭飞MCMS接口upload.do存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%93%AD%E9%A3%9E/%E9%93%AD%E9%A3%9EMCMS%E6%8E%A5%E5%8F%A3upload.do%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
OpenCart开源电子商务平台divido.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OpenCart/OpenCart%E5%BC%80%E6%BA%90%E7%94%B5%E5%AD%90%E5%95%86%E5%8A%A1%E5%B9%B3%E5%8F%B0divido.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
D-LINK-DIR-845L接口bsc_sms_inbox.php存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-LINK-DIR-845L%E6%8E%A5%E5%8F%A3bsc_sms_inbox.php%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
致远互联FE协作办公平台codeMoreWidget.js存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94FE%E5%8D%8F%E4%BD%9C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0codeMoreWidget.js%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
飞企互联-FE企业运营管理平台efficientCodewidget39接口SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0_efficientCodewidget39%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金和OA-C6接口DownLoadBgImage存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA-C6%E6%8E%A5%E5%8F%A3DownLoadBgImage%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240621-新增漏洞
真内控国产化开发平台接口preview任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%9C%9F%E5%86%85%E6%8E%A7%E5%9B%BD%E4%BA%A7%E5%8C%96%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0/%E7%9C%9F%E5%86%85%E6%8E%A7%E5%9B%BD%E4%BA%A7%E5%8C%96%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0%E6%8E%A5%E5%8F%A3preview%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
华测监测预警系统接口UserEdit.aspx存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E6%B5%8B%E7%9B%91%E6%B5%8B%E9%A2%84%E8%AD%A6%E7%B3%BB%E7%BB%9F/%E5%8D%8E%E6%B5%8B%E7%9B%91%E6%B5%8B%E9%A2%84%E8%AD%A6%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3UserEdit.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
ShokoServer系统withpath任意文件读取漏洞(CVE-2023-43662)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ShokoServer/ShokoServer%E7%B3%BB%E7%BB%9Fwithpath%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2023-43662).md
契约锁电子签章平台add远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%91%E7%BA%A6%E9%94%81%E7%94%B5%E5%AD%90%E7%AD%BE%E7%AB%A0%E7%B3%BB%E7%BB%9F/%E5%A5%91%E7%BA%A6%E9%94%81%E7%94%B5%E5%AD%90%E7%AD%BE%E7%AB%A0%E5%B9%B3%E5%8F%B0add%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
Zyxel-NAS设备setCookie未授权命令注入漏洞(CVE-2024-29973)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Zyxe%20NAS/Zyxel-NAS%E8%AE%BE%E5%A4%87setCookie%E6%9C%AA%E6%8E%88%E6%9D%83%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-29973).md
新视窗新一代物业管理系统GetCertificateInfoByStudentId存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B0%E8%A7%86%E7%AA%97%E6%96%B0%E4%B8%80%E4%BB%A3%E7%89%A9%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%96%B0%E8%A7%86%E7%AA%97%E6%96%B0%E4%B8%80%E4%BB%A3%E7%89%A9%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetCertificateInfoByStudentId%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
XWiki-Platform远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/XWiki/XWiki-Platform%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
学分制系统GetCalendarContentById存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AD%A6%E5%88%86%E5%88%B6%E7%B3%BB%E7%BB%9F/%E5%AD%A6%E5%88%86%E5%88%B6%E7%B3%BB%E7%BB%9FGetCalendarContentById%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
云匣子系统接口ssoToolReport存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E5%8C%A3%E5%AD%90%E5%A0%A1%E5%9E%92%E6%9C%BA/%E4%BA%91%E5%8C%A3%E5%AD%90%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3ssoToolReport%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
泛微E-Cology-KtreeUploadAction任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology-KtreeUploadAction%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
极限OA接口video_file.php存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%9E%81%E9%99%90OA/%E6%9E%81%E9%99%90OA%E6%8E%A5%E5%8F%A3video_file.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
锐捷上网行为管理系统static_convert.php存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fstatic_convert.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
佑友防火墙后台接口download存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BD%91%E5%8F%8B%E9%98%B2%E7%81%AB%E5%A2%99/%E4%BD%91%E5%8F%8B%E9%98%B2%E7%81%AB%E5%A2%99%E5%90%8E%E5%8F%B0%E6%8E%A5%E5%8F%A3download%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
佑友防火墙后台接口maintain存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BD%91%E5%8F%8B%E9%98%B2%E7%81%AB%E5%A2%99/%E4%BD%91%E5%8F%8B%E9%98%B2%E7%81%AB%E5%A2%99%E5%90%8E%E5%8F%B0%E6%8E%A5%E5%8F%A3maintain%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
极企智能办公路由接口jumper.php存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/%E6%9E%81%E4%BC%81%E6%99%BA%E8%83%BD%E5%8A%9E%E5%85%AC%E8%B7%AF%E7%94%B1%E6%8E%A5%E5%8F%A3jumper.php%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
用友Ufida-ELTextFile.load.d任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BUfida-ELTextFile.load.d%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
易天智能eHR管理平台任意用户添加漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%A4%A9%E6%99%BA%E8%83%BDeHR%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E6%98%93%E5%A4%A9%E6%99%BA%E8%83%BDeHR%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md
多客圈子论坛前台SSRF漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%9A%E5%AE%A2%E5%9C%88%E5%AD%90%E8%AE%BA%E5%9D%9B%E7%B3%BB%E7%BB%9F/%E5%A4%9A%E5%AE%A2%E5%9C%88%E5%AD%90%E8%AE%BA%E5%9D%9B%E5%89%8D%E5%8F%B0SSRF%E6%BC%8F%E6%B4%9E.md
APP分发签名系统index-uplog.php存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%88%86%E5%8F%91%E7%AD%BE%E5%90%8D%E7%B3%BB%E7%BB%9F/APP%E5%88%86%E5%8F%91%E7%AD%BE%E5%90%8D%E7%B3%BB%E7%BB%9Findex-uplog.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240618-新增漏洞
禅道18.5存在后台命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%9318.5%E5%AD%98%E5%9C%A8%E5%90%8E%E5%8F%B0%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
Fastadmin框架存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Fastadmin/Fastadmin%E6%A1%86%E6%9E%B6%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
CRMEB开源商城v5.2.2存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/CRMEB/CRMEB%E5%BC%80%E6%BA%90%E5%95%86%E5%9F%8Ev5.2.2%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
AEGON-LIFEv1.0存在SQL注入漏洞(CVE-2024-36597)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AEGON/AEGON-LIFEv1.0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-36597).md
悦库企业网盘userlogin.html存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%82%A6%E5%BA%93%E4%BC%81%E4%B8%9A%E7%BD%91%E7%9B%98/%E6%82%A6%E5%BA%93%E4%BC%81%E4%B8%9A%E7%BD%91%E7%9B%98userlogin.html%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
仿新浪外汇余额宝时间交易所任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%A4%E6%98%93%E6%89%80%E7%B3%BB%E7%BB%9F/%E4%BB%BF%E6%96%B0%E6%B5%AA%E5%A4%96%E6%B1%87%E4%BD%99%E9%A2%9D%E5%AE%9D%E6%97%B6%E9%97%B4%E4%BA%A4%E6%98%93%E6%89%80%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
申瓯通信在线录音管理系统download任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B3%E7%93%AF%E9%80%9A%E4%BF%A1%E5%9C%A8%E7%BA%BF%E5%BD%95%E9%9F%B3%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E7%94%B3%E7%93%AF%E9%80%9A%E4%BF%A1%E5%9C%A8%E7%BA%BF%E5%BD%95%E9%9F%B3%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdownload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
致远互联FE协作办公平台ncsubjass存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94FE%E5%8D%8F%E4%BD%9C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0ncsubjass%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
世邦通信SPON-IP网络对讲广播系统my_parser.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1SPON-IP%E7%BD%91%E7%BB%9C%E5%AF%B9%E8%AE%B2%E5%B9%BF%E6%92%AD%E7%B3%BB%E7%BB%9Fmy_parser.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
万户-ezOFFICE-download_ftp.jsp任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7-ezOFFICE-download_ftp.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
平升水库水文监测系统默认密码https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%B3%E5%8D%87%E7%94%B5%E5%AD%90%E6%B0%B4%E5%BA%93%E7%9B%91%E7%AE%A1%E5%B9%B3%E5%8F%B0/%E5%B9%B3%E5%8D%87%E6%B0%B4%E5%BA%93%E6%B0%B4%E6%96%87%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9F%E9%BB%98%E8%AE%A4%E5%AF%86%E7%A0%81.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240614-新增漏洞
致远oa系统saveFormula4Cloud存在JNDI注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9Coa%E7%B3%BB%E7%BB%9FsaveFormula4Cloud%E5%AD%98%E5%9C%A8JNDI%E6%B3%A8%E5%85%A5.md
用友NC-oacoSchedulerEvents接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-oacoSchedulerEvents%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
致远OA帆软组件ReportServer目录遍历漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%E5%B8%86%E8%BD%AF%E7%BB%84%E4%BB%B6ReportServer%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md
泛微-eoffice-webservice-file-upload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE-eoffice-webservice-file-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微e-office-mobile_upload_save存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office-mobile_upload_save%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微e-office-uploadify.php存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office-uploadify.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
世邦通信SPON-IP网络对讲广播系统addscenedata.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1/%E4%B8%96%E9%82%A6%E9%80%9A%E4%BF%A1SPON-IP%E7%BD%91%E7%BB%9C%E5%AF%B9%E8%AE%B2%E5%B9%BF%E6%92%AD%E7%B3%BB%E7%BB%9Faddscenedata.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
电信网关配置管理后台del_file.php接口存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86%E5%90%8E%E5%8F%B0del_file.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
Ivanti-EPM存在SQL注入漏洞(CVE-2024-29824)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ivanti/Ivanti-EPM%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-29824).md
JEPaaS低代码平台j_spring_security_check存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0j_spring_security_check%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
东胜物流软件GetProParentModuTreeList存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E8%83%9C%E7%89%A9%E6%B5%81%E8%BD%AF%E4%BB%B6/%E4%B8%9C%E8%83%9C%E7%89%A9%E6%B5%81%E8%BD%AF%E4%BB%B6GetProParentModuTreeList%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
锐捷NBR系列路由器存在管理员密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7NBR%E7%B3%BB%E5%88%97%E8%B7%AF%E7%94%B1%E5%99%A8%E5%AD%98%E5%9C%A8%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
海洋CMS-admin_notify.php远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E6%B4%8Bcms/%E6%B5%B7%E6%B4%8BCMS-admin_notify.php%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
SolarWinds-Serv-U目录遍历漏洞(CVE-2024-28995)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SolarWinds%20Serv%20U/SolarWinds-Serv-U%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E(CVE-2024-28995).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240611-新增漏洞
海康威视综合安防管理平台keepAlive远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0keepAlive%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
金和OA-C6-download.jsp任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA-C6-download.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
锐捷校园网自助服务系统login_judge.jsf任意文件读取漏洞(XVE-2024-2116)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E6%A0%A1%E5%9B%AD%E7%BD%91%E8%87%AA%E5%8A%A9%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Flogin_judge.jsf%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(XVE-2024-2116).md
HFS2.3未经身份验证的远程代码执行(CVE-2024-23692)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/HSF/HFS2.3%E6%9C%AA%E7%BB%8F%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%9A%84%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C(CVE-2024-23692).md
29网课交单平台epay.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E8%AF%BE%E4%BA%A4%E5%8D%95%E5%B9%B3%E5%8F%B0/29%E7%BD%91%E8%AF%BE%E4%BA%A4%E5%8D%95%E5%B9%B3%E5%8F%B0epay.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
多客圈子论坛系统httpGet任意文件读取漏洞复现https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%9A%E5%AE%A2%E5%9C%88%E5%AD%90%E8%AE%BA%E5%9D%9B%E7%B3%BB%E7%BB%9F/%E5%A4%9A%E5%AE%A2%E5%9C%88%E5%AD%90%E8%AE%BA%E5%9D%9B%E7%B3%BB%E7%BB%9FhttpGet%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240607-新增漏洞
天智云智造管理平台Usermanager.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%99%BA%E4%BA%91/%E5%A4%A9%E6%99%BA%E4%BA%91%E6%99%BA%E9%80%A0%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0Usermanager.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
海康威视综合安防管理平台productFile远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0productFile%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
海康威视综合安防管理平台applyAutoLoginTicket远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0applyAutoLoginTicket%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
showdoc3.2.4-phar反序列漏洞复现https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/showdoc/showdoc3.2.4-phar%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0.md
Progress-Telerik-Report-Server身份验证绕过(CVE-2024-4358)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Progress/Progress-Telerik-Report-Server%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87(CVE-2024-4358).md
悟空CRM9.0-fastjson远程代码执行漏洞(CVE-2024-23052)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%82%9F%E7%A9%BACRM/%E6%82%9F%E7%A9%BACRM9.0-fastjson%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-23052).md
PHP-CGI-Windows平台远程代码执行漏洞(CVE-2024-4577)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/php/PHP-CGI-Windows%E5%B9%B3%E5%8F%B0%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-4577).md
用友NC-downCourseWare任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-downCourseWare%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
用友-U9-PatchFile.asmx任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B-U9-PatchFile.asmx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Apache-HugeGraph-Server远程代码执行漏洞(CVE-2024-27348)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-HugeGraph-Server%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-27348).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240605-新增漏洞
Symfony-app_dev.php信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Symfony/Symfony-app_dev.php%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
泛微OA-E-cology8-SptmForPortalThumbnail.jsp任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-cology8-SptmForPortalThumbnail.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
O2OA远程命令执行(CVE-2022-22916)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/O2OA/O2OA%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C(CVE-2022-22916).md
大华DSS城市安防监控平台login_init.action接口存在Struct2-045命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EDSS%E5%9F%8E%E5%B8%82%E5%AE%89%E9%98%B2%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0login_init.action%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8Struct2-045%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
H3C-CVM-upload接口前台任意文件上传漏洞复现https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-CVM-upload%E6%8E%A5%E5%8F%A3%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0.md
用友NC-pagesServlet存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-pagesServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
宏景HCM-pos_dept_post存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFHCM-pos_dept_post%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
迈普多业务融合网关send_order.cgi存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%BF%88%E6%99%AE%E5%A4%9A%E4%B8%9A%E5%8A%A1%E8%9E%8D%E5%90%88%E7%BD%91%E5%85%B3/%E8%BF%88%E6%99%AE%E5%A4%9A%E4%B8%9A%E5%8A%A1%E8%9E%8D%E5%90%88%E7%BD%91%E5%85%B3send_order.cgi%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
HSC-Mailinspector-loader.php存在任意文件读取漏洞(CVE-2024-34470)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/HSC/HSC-Mailinspector-loader.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-34470).md
Minio-verify信息泄露(CVE-2023-28432)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Minio/Minio-verify%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2(CVE-2023-28432).md
OrangeHRM-viewProjects接口存在SQL注入漏洞(CVE-2024-36428)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OrangeHRM/OrangeHRM-viewProjects%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-36428).md
ShowDoc3.2.5存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/showdoc/ShowDoc3.2.5%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
mysql2原型污染漏洞(CVE-2024-21512)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/mysql2/mysql2%E5%8E%9F%E5%9E%8B%E6%B1%A1%E6%9F%93%E6%BC%8F%E6%B4%9E(CVE-2024-21512).md
亿赛通-电子文档安全管理系统SaveCDGPermissionFromGFOA接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A-%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSaveCDGPermissionFromGFOA%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Apache-OFBiz存在路径遍历导致RCE漏洞(CVE-2024-36104)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-OFBiz%E5%AD%98%E5%9C%A8%E8%B7%AF%E5%BE%84%E9%81%8D%E5%8E%86%E5%AF%BC%E8%87%B4RCE%E6%BC%8F%E6%B4%9E(CVE-2024-36104).md
飞企互联-FE企业运营管理平台treeXml.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0treeXml.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-Office-json_common.phpSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office-json_common.phpSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-Office系统login_other.php存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office%E7%B3%BB%E7%BB%9Flogin_other.php%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240602-新增漏洞
海康威视综合安防download存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2download%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
科讯图书馆综合管理云平台WebCloud.asmx存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%AE%AF%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BA%91%E5%B9%B3%E5%8F%B0/%E7%A7%91%E8%AE%AF%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E4%BA%91%E5%B9%B3%E5%8F%B0WebCloud.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
翰智员工服务平台loginByPassword存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BF%B0%E6%99%BA%E5%91%98%E5%B7%A5%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0/%E7%BF%B0%E6%99%BA%E5%91%98%E5%B7%A5%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0loginByPassword%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
DT高清车牌识别摄像机存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/DT/DT%E9%AB%98%E6%B8%85%E8%BD%A6%E7%89%8C%E8%AF%86%E5%88%AB%E6%91%84%E5%83%8F%E6%9C%BA%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
showDoc-uploadImg任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/showdoc/showDoc-uploadImg%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
全程云OA-svc.asmxSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%A8%E7%A8%8B%E4%BA%91OA/%E5%85%A8%E7%A8%8B%E4%BA%91OA-svc.asmxSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微OA-E-Mobile移动管理平台lang2sql任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Mobile%E7%A7%BB%E5%8A%A8%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0lang2sql%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
金蝶云星空UserService反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6%E4%BA%91%E6%98%9F%E7%A9%BAUserService%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
湖南建研检测系统存在DownLoad2.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8DownLoad2.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240531-新增漏洞
PHP-Live-Chat代码审计之组合拳GetShellhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PHP%20Live%20Chat/PHP-Live-Chat%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E4%B9%8B%E7%BB%84%E5%90%88%E6%8B%B3GetShell.md
宏景eHR-showmedia.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR-showmedia.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
NextGen-Mirth-Connect-XStream反序列化远程代码执行漏洞(CVE-2023-43208)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/NextGen/NextGen-Mirth-Connect-XStream%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-43208).md
用友智石开PLM-getWorkGroups存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%99%BA%E7%9F%B3%E5%BC%80PLM-getWorkGroups%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
智邦国际ERP-GetPersonalSealData.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E9%82%A6%E5%9B%BD%E9%99%85ERP/%E6%99%BA%E9%82%A6%E5%9B%BD%E9%99%85ERP-GetPersonalSealData.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
中成科信票务管理系统ReserveTicketManagerPlane.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FReserveTicketManagerPlane.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
JEPaaS低代码平台document存在文件上传致RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0/JEPaaS%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%B9%B3%E5%8F%B0document%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E8%87%B4RCE%E6%BC%8F%E6%B4%9E.md
大华城市安防监控系统平台管理存在user_edit.action信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E5%9F%8E%E5%B8%82%E5%AE%89%E9%98%B2%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9F%E5%B9%B3%E5%8F%B0%E7%AE%A1%E7%90%86%E5%AD%98%E5%9C%A8user_edit.action%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
Check-Point安全网关任意文件读取漏洞(CVE-2024-24919)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Check%20Point%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3/Check-Point%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-24919).md
电信网关配置管理后台rewrite.php接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86%E5%90%8E%E5%8F%B0rewrite.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240528-新增漏洞
DCN有线无线智能一体化控制器WEB管理系统https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/DCN/DCN%E6%9C%89%E7%BA%BF%E6%97%A0%E7%BA%BF%E6%99%BA%E8%83%BD%E4%B8%80%E4%BD%93%E5%8C%96%E6%8E%A7%E5%88%B6%E5%99%A8WEB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F.md
用友NC系统linkVoucher存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9FlinkVoucher%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
锐捷RG-UAC统一上网行为管理审计系统online.php存在远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fonline.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
锐捷RG-UAC统一上网行为管理审计系统static_route_edit_ipv6.php存在远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fstatic_route_edit_ipv6.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
锐捷RG-UAC统一上网行为管理审计系统sub_commit.php存在远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fsub_commit.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
锐捷RG-UAC统一上网行为管理审计系统user_commit.php存在远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fuser_commit.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
锐捷RG-UAC统一上网行为管理审计系统vlan_add_commit.php存在远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Fvlan_add_commit.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
大华智慧园区综合管理平台user_getUserInfoByUserName.action未授权任意用户密码读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0user_getUserInfoByUserName.action%E6%9C%AA%E6%8E%88%E6%9D%83%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E8%AF%BB%E5%8F%96.md
锐捷RG-EW1200G无线路由器登录绕过https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-EW1200G%E6%97%A0%E7%BA%BF%E8%B7%AF%E7%94%B1%E5%99%A8%E7%99%BB%E5%BD%95%E7%BB%95%E8%BF%87.md
Jeecg-jeecgFormDemoController存在JNDI代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeecgBoot/Jeecg-jeecgFormDemoController%E5%AD%98%E5%9C%A8JNDI%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
WordPress-Dropdown-CF7插件存在sql注入漏洞(CVE-2024-3495)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-Dropdown-CF7%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-3495).md
WordPress-WebDirectory插件存在sql注入(CVE-2024-3552)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-WebDirectory%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5(CVE-2024-3552).md
WordPress的Business-Directory插件存在sql注入漏洞(CVE-2024-4443)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E7%9A%84Business-Directory%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-4443).md
因酷教育软件开源网校程序gok4任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%9B%A0%E9%85%B7%E6%95%99%E8%82%B2%E8%BD%AF%E4%BB%B6/%E5%9B%A0%E9%85%B7%E6%95%99%E8%82%B2%E8%BD%AF%E4%BB%B6%E5%BC%80%E6%BA%90%E7%BD%91%E6%A0%A1%E7%A8%8B%E5%BA%8Fgok4%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240525-新增漏洞
瑞星EDR-XSS漏洞可打管理员cookiehttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E6%98%9FEDR/%E7%91%9E%E6%98%9FEDR-XSS%E6%BC%8F%E6%B4%9E%E5%8F%AF%E6%89%93%E7%AE%A1%E7%90%86%E5%91%98cookie.md
金山云EDR任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%B1%B1/%E9%87%91%E5%B1%B1%E4%BA%91EDR%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
HM发卡网反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8F%91%E5%8D%A1%E7%BD%91%E7%B3%BB%E7%BB%9F/HM%E5%8F%91%E5%8D%A1%E7%BD%91%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
Nexus未授权目录穿越漏洞(CVE-2024-4956)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Nexus/Nexus%E6%9C%AA%E6%8E%88%E6%9D%83%E7%9B%AE%E5%BD%95%E7%A9%BF%E8%B6%8A%E6%BC%8F%E6%B4%9E(CVE-2024-4956).md
泛微E-cology-LoginSSO.jsp存在QL注入漏洞(CNVD-2021-33202)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-cology-LoginSSO.jsp%E5%AD%98%E5%9C%A8QL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CNVD-2021-33202).md
万户ezEIP-success.aspx存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezEIP-success.aspx%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
通天星CMSV6车载定位监控平台SQL注入漏洞(XVE-2023-23744)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E5%AE%9A%E4%BD%8D%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(XVE-2023-23744).md
通天星CMSV6车载视频监控平台getAlser.acion接口处存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0getAlser.acion%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
通天星CMSV6车载视频监控平台xz_center信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0xz_center%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
智慧校园(安校易)管理系统FileUpProductupdate.aspx任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD(%E5%AE%89%E6%A0%A1%E6%98%93)%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%99%BA%E6%85%A7%E6%A0%A1%E5%9B%AD(%E5%AE%89%E6%A0%A1%E6%98%93)%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FFileUpProductupdate.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微E-Office10-OfficeServer任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office10-OfficeServer%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
ArubaOS-RCE漏洞(CVE-2024-26304)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Aruba/ArubaOS-RCE%E6%BC%8F%E6%B4%9E(CVE-2024-26304).md
H3C路由器userLogin.asp信息泄漏漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C%E8%B7%AF%E7%94%B1%E5%99%A8userLogin.asp%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md
用友nc电子采购信息系统securitycheck存在sql注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bnc%E7%94%B5%E5%AD%90%E9%87%87%E8%B4%AD%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9Fsecuritycheck%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5.md
用友NC-warningDetailInfo接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-warningDetailInfo%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Confluence远程命令执行漏洞(CVE-2024-21683)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Confluence/Confluence%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-21683).md
蓝海卓越计费管理系统存在debug.php远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8debug.php%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
蓝海卓越计费管理系统存在download.php任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8download.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240523-新增漏洞
致远OAV52019系统properties信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COAV52019%E7%B3%BB%E7%BB%9Fproperties%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
GeoServer系统wms接口存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/GeoServer/GeoServer%E7%B3%BB%E7%BB%9Fwms%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友NC-complainbilldetail存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-complainbilldetail%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-downTax存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-downTax%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR-OutputCode存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR-OutputCode%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud-linkntb.jsp存在SQL注入漏洞(CNVD-C-2023-708748)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud-linkntb.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CNVD-C-2023-708748).md
懒人网址导航页search.html存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%87%92%E4%BA%BA%E7%BD%91%E5%9D%80%E5%AF%BC%E8%88%AA%E9%A1%B5/%E6%87%92%E4%BA%BA%E7%BD%91%E5%9D%80%E5%AF%BC%E8%88%AA%E9%A1%B5search.html%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
LVS精益价值管理系统LVS.Web.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FLVS.Web.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
LVS精益价值管理系统DownLoad.aspx存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/LVS%E7%B2%BE%E7%9B%8A%E4%BB%B7%E5%80%BC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDownLoad.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微OA-E-Cology-Getdata.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Cology-Getdata.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
蓝海卓越计费管理系统SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E8%93%9D%E6%B5%B7%E5%8D%93%E8%B6%8A%E8%AE%A1%E8%B4%B9%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
铭飞CMS-search接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%93%AD%E9%A3%9E/%E9%93%AD%E9%A3%9ECMS-search%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240521-新增漏洞
QNAP-QTS溢出导致的未授权RCE漏洞(CVE-2024-27130)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/QNAP/QNAP-QTS%E6%BA%A2%E5%87%BA%E5%AF%BC%E8%87%B4%E7%9A%84%E6%9C%AA%E6%8E%88%E6%9D%83RCE%E6%BC%8F%E6%B4%9E(CVE-2024-27130).md
Zabbix-Serve-SQL注入漏洞(CVE-2024-22120)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Zabbix/Zabbix-Serve-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-22120).md
山东聚恒网络技术有限公司聚恒中台data.ashx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B1%B1%E4%B8%9C%E8%81%9A%E6%81%92%E7%BD%91%E7%BB%9C%E6%8A%80%E6%9C%AF%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8/%E5%B1%B1%E4%B8%9C%E8%81%9A%E6%81%92%E7%BD%91%E7%BB%9C%E6%8A%80%E6%9C%AF%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E8%81%9A%E6%81%92%E4%B8%AD%E5%8F%B0data.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
方正畅享全媒体新闻采编系统binary.do存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B9%E6%AD%A3%E5%85%A8%E5%AA%92%E4%BD%93/%E6%96%B9%E6%AD%A3%E7%95%85%E4%BA%AB%E5%85%A8%E5%AA%92%E4%BD%93%E6%96%B0%E9%97%BB%E9%87%87%E7%BC%96%E7%B3%BB%E7%BB%9Fbinary.do%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Git远程代码执行漏洞(CVE-2024-32002)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Git/Git%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-32002).md
Gradio存在任意文件读取漏洞(CVE-2024-1561)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Gradio/Gradio%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-1561).md
EasyCVR视频管理平台存在任意用户添加漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud系统XChangeServlet接口存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9FXChangeServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
emlog后台插件任意文件上传(CVE-2024-33752)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Emlog/emlog%E5%90%8E%E5%8F%B0%E6%8F%92%E4%BB%B6%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0(CVE-2024-33752).md
泛微OA-E-Cology-JqueryFileTree.jsp目录遍历漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Cology-JqueryFileTree.jsp%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md
cockpit系统upload接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/cockpit/cockpit%E7%B3%BB%E7%BB%9Fupload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
宏景HCM系统fieldsettree接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFHCM%E7%B3%BB%E7%BB%9Ffieldsettree%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240518-新增漏洞
英飞达医学影像存档与通信系统WebJobUpload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6%E5%BD%B1%E5%83%8F%E5%AD%98%E6%A1%A3%E4%B8%8E%E9%80%9A%E4%BF%A1%E7%B3%BB%E7%BB%9F/%E8%8B%B1%E9%A3%9E%E8%BE%BE%E5%8C%BB%E5%AD%A6%E5%BD%B1%E5%83%8F%E5%AD%98%E6%A1%A3%E4%B8%8E%E9%80%9A%E4%BF%A1%E7%B3%BB%E7%BB%9FWebJobUpload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
佳会视频会议attachment任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BD%B3%E4%BC%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AE/%E4%BD%B3%E4%BC%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AEattachment%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
六零导航页存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%AD%E9%9B%B6%E5%AF%BC%E8%88%AA%E9%A1%B5/%E5%85%AD%E9%9B%B6%E5%AF%BC%E8%88%AA%E9%A1%B5%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
SeaCMS海洋影视管理系统dmku存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E6%B4%8Bcms/SeaCMS%E6%B5%B7%E6%B4%8B%E5%BD%B1%E8%A7%86%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdmku%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友CRM系统uploadfile.php接口存在任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BCRM%E7%B3%BB%E7%BB%9Fuploadfile.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
安达通TPN-2G安全网关远程代码执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%89%E8%BE%BE%E9%80%9A/%E5%AE%89%E8%BE%BE%E9%80%9ATPN-2G%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C.md
科拓全智能停车收费系统DoubtCarNoListFrom.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E6%8B%93%E5%85%A8%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9F/%E7%A7%91%E6%8B%93%E5%85%A8%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9FDoubtCarNoListFrom.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
科拓全智能停车收费系统Webservice.asmx存在任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E6%8B%93%E5%85%A8%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9F/%E7%A7%91%E6%8B%93%E5%85%A8%E6%99%BA%E8%83%BD%E5%81%9C%E8%BD%A6%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9FWebservice.asmx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
D-LINK-DIR-X4860未授权RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-LINK-DIR-X4860%E6%9C%AA%E6%8E%88%E6%9D%83RCE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240513-新增漏洞
用友NC系统registerServlet接口存在JNDI注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9FregisterServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8JNDI%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
微擎-AccountEdit-file-upload文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BE%AE%E6%93%8E/%E5%BE%AE%E6%93%8E-AccountEdit-file-upload%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
RuvarOA协同办公平台多处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/RuvarOA%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0/RuvarOA%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0%E5%A4%9A%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
微厦在线学习平台OrganSetup存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%BE%AE%E5%8E%A6%E5%9C%A8%E7%BA%BF%E5%AD%A6%E4%B9%A0%E5%B9%B3%E5%8F%B0/%E5%BE%AE%E5%8E%A6%E5%9C%A8%E7%BA%BF%E5%AD%A6%E4%B9%A0%E5%B9%B3%E5%8F%B0OrganSetup%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微E-Cology系统接口SignatureDownLoad存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Cology%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3SignatureDownLoad%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC系统printBill接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9FprintBill%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微-OA系统ResourceServlet接口任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE-OA%E7%B3%BB%E7%BB%9FResourceServlet%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
锐捷网络flwo.control.php存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E7%BD%91%E7%BB%9Cflwo.control.php%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统-UploadFileManagerService-任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-UploadFileManagerService-%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
大华ICC智能物联综合管理平台存在fastjson漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EICC%E6%99%BA%E8%83%BD%E7%89%A9%E8%81%94%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8fastjson%E6%BC%8F%E6%B4%9E.md
联软安渡UniNXG安全数据交换系统poserver.zz存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BD%AF/%E8%81%94%E8%BD%AF%E5%AE%89%E6%B8%A1UniNXG%E5%AE%89%E5%85%A8%E6%95%B0%E6%8D%AE%E4%BA%A4%E6%8D%A2%E7%B3%BB%E7%BB%9Fposerver.zz%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
世纪信通管理系统DownLoadFiles.ashx存在任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%96%E7%BA%AA%E4%BF%A1%E9%80%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%B8%96%E7%BA%AA%E4%BF%A1%E9%80%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDownLoadFiles.ashx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
亿赛通电子文档安全管理系统downloadfromfile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdownloadfromfile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240508-新增漏洞
用友畅捷通TPlus-keyEdit.aspx接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ATPlus-keyEdit.aspx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友时空KSOA-linkadd.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA-linkadd.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
MetaCRM客户关系管理系统任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/MetaCRM/MetaCRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友U8-CRM客户关系管理系统getemaildata.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fgetemaildata.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
电信网关配置管理后台ipping.php存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86/%E7%94%B5%E4%BF%A1%E7%BD%91%E5%85%B3%E9%85%8D%E7%BD%AE%E7%AE%A1%E7%90%86%E5%90%8E%E5%8F%B0ipping.php%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
瑞友天翼应用虚拟化系统appsave接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E5%8F%8B%E5%A4%A9%E7%BF%BC%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9F/%E7%91%9E%E5%8F%8B%E5%A4%A9%E7%BF%BC%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9Fappsave%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微OA-E-Cology-FileDownload文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA-E-Cology-FileDownload%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友GRPA++Cloud政府财务云存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRPA++Cloud%E6%94%BF%E5%BA%9C%E8%B4%A2%E5%8A%A1%E4%BA%91%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
红海云eHR-PtFjk.mob存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR/%E7%BA%A2%E6%B5%B7%E4%BA%91eHR-PtFjk.mob%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
福建科立讯通信指挥调度管理平台ajax_users.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1%E6%8C%87%E6%8C%A5%E8%B0%83%E5%BA%A6%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0ajax_users.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金和OAC6-FileDownLoad.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COAC6-FileDownLoad.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
F5-BIG-IP存在SQL注入漏洞(CVE-2024-26026)&(CVE-2024-21793)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/F5-BIG-IP/F5-BIG-IP%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-26026)&(CVE-2024-21793).md
Mura-CMS-processAsyncObject存在SQL注入漏洞(CVE-2024-32640)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Mura/Mura-CMS-processAsyncObject%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-32640).md
中移铁通禹路由器信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/%E4%B8%AD%E7%A7%BB%E9%93%81%E9%80%9A%E7%A6%B9%E8%B7%AF%E7%94%B1%E5%99%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
致远M3敏感信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9CM3%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
Jan任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Jan/Jan%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Jeecg任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeecgBoot/Jeecg%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
医院挂号系统SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%BB%E9%99%A2%E6%8C%82%E5%8F%B7%E7%B3%BB%E7%BB%9F/%E5%8C%BB%E9%99%A2%E6%8C%82%E5%8F%B7%E7%B3%BB%E7%BB%9FSQL%E6%B3%A8%E5%85%A5.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240502-新增漏洞
和丰多媒体信息发布系统QH.aspx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%92%8C%E4%B8%B0%E5%A4%9A%E5%AA%92%E4%BD%93%E4%BF%A1%E6%81%AF%E5%8F%91%E5%B8%83%E7%B3%BB%E7%BB%9F/%E5%92%8C%E4%B8%B0%E5%A4%9A%E5%AA%92%E4%BD%93%E4%BF%A1%E6%81%AF%E5%8F%91%E5%B8%83%E7%B3%BB%E7%BB%9FQH.aspx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-bill存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-bill%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-CRM客户关系管理系统downloadfile.php存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdownloadfile.php%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
OpenMetadata-SpEL注入(CVE-2024-28848)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OpenMetadata/OpenMetadata-SpEL%E6%B3%A8%E5%85%A5(CVE-2024-28848).md
OpenMetadata命令执行漏洞(CVE-2024-28253)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OpenMetadata/OpenMetadata%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-28253).md
Ncast高清智能录播系统存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
AJ-Report开源数据大屏存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AJ-Report/AJ-Report%E5%BC%80%E6%BA%90%E6%95%B0%E6%8D%AE%E5%A4%A7%E5%B1%8F%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
大华智慧园区综合管理平台ipms接口存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0ipms%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240430-新增漏洞
亿赛通电子文档安全管理系统-jlockseniordao-findbylockname-sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-jlockseniordao-findbylockname-sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统-MailMessageLogServices反序列漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-MailMessageLogServices%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统RestoreFiles任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FRestoreFiles%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
蓝网科技临床浏览系统-deleteStudy-SQL注入漏洞复现(CVE-2024-4257)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E7%BD%91%E7%A7%91%E6%8A%80%E4%B8%B4%E5%BA%8A%E6%B5%8F%E8%A7%88%E7%B3%BB%E7%BB%9F/%E8%93%9D%E7%BD%91%E7%A7%91%E6%8A%80%E4%B8%B4%E5%BA%8A%E6%B5%8F%E8%A7%88%E7%B3%BB%E7%BB%9F-deleteStudy-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2024-4257).md
Pkpmbs建设工程质量监督系统FileUpOrDown.ashx存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Pkpmbs%E5%BB%BA%E8%AE%BE%E5%B7%A5%E7%A8%8B%E8%B4%A8%E9%87%8F%E7%9B%91%E7%9D%A3%E7%B3%BB%E7%BB%9F/Pkpmbs%E5%BB%BA%E8%AE%BE%E5%B7%A5%E7%A8%8B%E8%B4%A8%E9%87%8F%E7%9B%91%E7%9D%A3%E7%B3%BB%E7%BB%9FFileUpOrDown.ashx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Mingsoft-MCMS前台查询文章列表接口SQL注入(CNVD-2024-06148)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Mingsoft/Mingsoft-MCMS%E5%89%8D%E5%8F%B0%E6%9F%A5%E8%AF%A2%E6%96%87%E7%AB%A0%E5%88%97%E8%A1%A8%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5(CNVD-2024-06148).md
广州图书馆集群系统WebBookNew存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E5%88%9B%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%B3%BB%E7%BB%9FWebBookNew%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Likeshop-formimage任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Likeshop/Likeshop-formimage%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
X2Modbus网关GetUser接口存在信息泄漏漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/X2Modbus/X2Modbus%E7%BD%91%E5%85%B3GetUser%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md
WordPress-Automatic插件存在SQL注入漏洞(CVE-2024-27956)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-Automatic%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-27956).md
北京中科聚网一体化运营平台catchByUrl存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%97%E4%BA%AC%E4%B8%AD%E7%A7%91%E8%81%9A%E7%BD%91/%E5%8C%97%E4%BA%AC%E4%B8%AD%E7%A7%91%E8%81%9A%E7%BD%91%E4%B8%80%E4%BD%93%E5%8C%96%E8%BF%90%E8%90%A5%E5%B9%B3%E5%8F%B0catchByUrl%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
LiveGBS存在逻辑缺陷漏洞(CNVD-2023-72138)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LiveGBS/LiveGBS%E5%AD%98%E5%9C%A8%E9%80%BB%E8%BE%91%E7%BC%BA%E9%99%B7%E6%BC%8F%E6%B4%9E(CNVD-2023-72138).md
北京亚控科技KingPortal开发系统漏洞集合https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%97%E4%BA%AC%E4%BA%9A%E6%8E%A7%E7%A7%91%E6%8A%80/%E5%8C%97%E4%BA%AC%E4%BA%9A%E6%8E%A7%E7%A7%91%E6%8A%80KingPortal%E5%BC%80%E5%8F%91%E7%B3%BB%E7%BB%9F%E6%BC%8F%E6%B4%9E%E9%9B%86%E5%90%88.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240428-新增漏洞
用友GRP-U8-slbmbygr.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-slbmbygr.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友GRP-U8-listSelectDialogServlet存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-listSelectDialogServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
用友GRP-U8-bx_dj_check.jsp存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-bx_dj_check.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
用友GRP-U8-obr_zdybxd_check.jsp存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-obr_zdybxd_check.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
用友GRP-U8-userInfoWeb存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-userInfoWeb%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
用友GRP-U8-dialog_moreUser_check.jsp前台SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-dialog_moreUser_check.jsp%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5.md
用友GRP-U8-Proxy存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-Proxy%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友GRP-U8-sqcxIndex.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-sqcxIndex.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友GRP-U8-FileUpload任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-FileUpload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
用友GRP-U8-UploadFileData任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-UploadFileData%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
用友GRP-U8-ufgovbank存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-ufgovbank%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
用友GRP-U8-PayReturnForWcp接口存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-PayReturnForWcp%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
用友GRP-U8日志泄漏漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8%E6%97%A5%E5%BF%97%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240427-新增漏洞
通达OA-WHERE_STR存在前台SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA-WHERE_STR%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友GRP-U8-obr_zdybxd_check存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-obr_zdybxd_check%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友畅捷通TPlus-InitServerInfo存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ATPlus-InitServerInfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友畅捷通-TPlus-CheckMutex存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9A-TPlus-CheckMutex%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友畅捷通TPlus-DownloadProxy.aspx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ATPlus-DownloadProxy.aspx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友畅捷通CRM-create_site.phpSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ACRM-create_site.phpSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
MajorDoMo-thumb.php未授权RCE漏洞复现(CNVD-2024-02175)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/MajorDoMo/MajorDoMo-thumb.php%E6%9C%AA%E6%8E%88%E6%9D%83RCE%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CNVD-2024-02175).md
普元EOS-Platform-eos.jmx存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%AE%E5%85%83EOS-Platform/%E6%99%AE%E5%85%83EOS-Platform-eos.jmx%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
普元EOS-Platform-jmx.jmx存在远程代码执行漏洞(XVE-2023-24691)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%AE%E5%85%83EOS-Platform/%E6%99%AE%E5%85%83EOS-Platform-jmx.jmx%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(XVE-2023-24691).md
用友U8-Cloud-TableInputOperServlet存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud-TableInputOperServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
湖南建研质量监测系统upload.ashx文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94%E8%B4%A8%E9%87%8F%E7%9B%91%E6%B5%8B%E7%B3%BB%E7%BB%9Fupload.ashx%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
脸爱云一脸通智慧管理平台存在UpLoadPic.ashx文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8UpLoadPic.ashx%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
ZenML服务器远程权限提升漏洞(CVE-2024-25723)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/ZenML/ZenML%E6%9C%8D%E5%8A%A1%E5%99%A8%E8%BF%9C%E7%A8%8B%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E(CVE-2024-25723).md
WordPress插件NotificationX存在sql注入漏洞(CVE-2024-1698)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6NotificationX%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-1698).md
CrushFTP服务器端模板注入(CVE-2024-4040)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/CrushFTP/CrushFTP%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%AB%AF%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5(CVE-2024-4040).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240423-新增漏洞
网动统一通信平台ActiveUC存在任意文件下载漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%8A%A8%E7%BB%9F%E4%B8%80%E9%80%9A%E4%BF%A1%E5%B9%B3%E5%8F%B0/%E7%BD%91%E5%8A%A8%E7%BB%9F%E4%B8%80%E9%80%9A%E4%BF%A1%E5%B9%B3%E5%8F%B0ActiveUC%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
锐捷校园网自助服务系统operatorReportorRoamService存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E6%A0%A1%E5%9B%AD%E7%BD%91%E8%87%AA%E5%8A%A9%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9FoperatorReportorRoamService%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友政务财务系统FileDownload存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%94%BF%E5%8A%A1%E8%B4%A2%E5%8A%A1%E7%B3%BB%E7%BB%9FFileDownload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
F-logic_DataCube3存在SQL注入漏洞(CVE-2024-31750)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/F%20logic%20DataCube3/F-logic_DataCube3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-31750).md
用友移动系统管理uploadApk接口存在任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%A7%BB%E5%8A%A8%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86uploadApk%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
泛微e-office系统UserSelect接口存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office%E7%B3%BB%E7%BB%9FUserSelect%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
WIFISKY-7层流控路由器confirm.php接口处存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/WIFISKY-7%E5%B1%82%E6%B5%81%E6%8E%A7%E8%B7%AF%E7%94%B1%E5%99%A8confirm.php%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
泛微E-Office-uploadfile.php任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office-uploadfile.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
宏景HCM系统infoView处存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFHCM%E7%B3%BB%E7%BB%9FinfoView%E5%A4%84%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
卡车卫星定位系统create存在未授权密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%A1%E8%BD%A6%E5%8D%AB%E6%98%9F%E5%AE%9A%E4%BD%8D%E7%B3%BB%E7%BB%9F/%E5%8D%A1%E8%BD%A6%E5%8D%AB%E6%98%9F%E5%AE%9A%E4%BD%8D%E7%B3%BB%E7%BB%9Fcreate%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
脸爱云一脸通智慧管理平台存在downloads.aspx信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8downloads.aspx%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
脸爱云一脸通智慧平台SelOperators信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E5%B9%B3%E5%8F%B0SelOperators%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
禅道项目管理系统身份认证绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%85%E9%81%93/%E7%A6%85%E9%81%93%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240419-新增漏洞
用友U8GRP-fastjsonhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8GRP-fastjson%E6%BC%8F%E6%B4%9E.md
云时空社会化商业ERP系统validateLoginName接口处存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E6%97%B6%E7%A9%BA/%E4%BA%91%E6%97%B6%E7%A9%BA%E7%A4%BE%E4%BC%9A%E5%8C%96%E5%95%86%E4%B8%9AERP%E7%B3%BB%E7%BB%9FvalidateLoginName%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Linksys-RE7000无线扩展器命令执行漏洞(CVE-2024-25852)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Linksys/Linksys-RE7000%E6%97%A0%E7%BA%BF%E6%89%A9%E5%B1%95%E5%99%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-25852).md
IP-guard-WebServer存在权限绕过漏洞(QVD-2024-14103)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/IP%20guard%20WebServer/IP-guard-WebServer%E5%AD%98%E5%9C%A8%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E(QVD-2024-14103).md
用友GRP-U8-operOriztion存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-operOriztion%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
时空智友企业流程化管控系统formservice存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E6%97%B6%E7%A9%BA/%E6%97%B6%E7%A9%BA%E6%99%BA%E5%8F%8B%E4%BC%81%E4%B8%9A%E6%B5%81%E7%A8%8B%E5%8C%96%E7%AE%A1%E6%8E%A7%E7%B3%BB%E7%BB%9Fformservice%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-Office-jx2_config存在信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office-jx2_config%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
泛微E-Mobile-messageType.do存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Mobile-messageType.do%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
润乾报表dataSphereServlet任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8dataSphereServlet%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
若依后台定时任务存在SSRF漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/RuoYi/%E8%8B%A5%E4%BE%9D%E5%90%8E%E5%8F%B0%E5%AE%9A%E6%97%B6%E4%BB%BB%E5%8A%A1%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E.md
用友NC-showcontent接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-showcontent%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240416-新增漏洞
网康科技NS-ASG应用安全网关add_ikev2.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3add_ikev2.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网康科技NS-ASG应用安全网关config_ISCGroupNoCache.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3config_ISCGroupNoCache.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网康科技NS-ASG应用安全网关config_Anticrack.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3config_Anticrack.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网康科技NS-ASG应用安全网关add_postlogin.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3add_postlogin.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
广州图创图书馆集群管理系统updOpuserPw接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E5%88%9B%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E5%88%9B%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FupdOpuserPw%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-uploadControl接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-uploadControl%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
SpringBlade框架dict-biz接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/SpringBlade%E6%A1%86%E6%9E%B6dict-biz%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
通天星CMSV6车载视频监控平台downloadLogger接口任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD%E8%A7%86%E9%A2%91%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0downloadLogger%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Progress-Flowmon命令注入漏洞(CVE-2024-2389)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Progress/Progress-Flowmon%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-2389).md
kkFileView-v4.3.0-RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/kkFileView/kkFileView-v4.3.0-RCE.md
draytek路由器addrouting命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/draytek%E8%B7%AF%E7%94%B1%E5%99%A8addrouting%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
飞企互联-FE企业运营管理平台ProxyServletUti存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0ProxyServletUti%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
富通天下外贸ERP任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AF%8C%E9%80%9A%E5%A4%A9%E4%B8%8B%E5%A4%96%E8%B4%B8ERP/%E5%AF%8C%E9%80%9A%E5%A4%A9%E4%B8%8B%E5%A4%96%E8%B4%B8ERP%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC_grouptemplet文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC_grouptemplet%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-avatar接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-avatar%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
PAN-OS安全设备存在命令执行漏洞(CVE-2024-3400)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PAN-OS/PAN-OS%E5%AE%89%E5%85%A8%E8%AE%BE%E5%A4%87%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-3400).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240412-新增漏洞
新视窗新一代物业管理系统任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B0%E8%A7%86%E7%AA%97%E6%96%B0%E4%B8%80%E4%BB%A3%E7%89%A9%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%96%B0%E8%A7%86%E7%AA%97%E6%96%B0%E4%B8%80%E4%BB%A3%E7%89%A9%E4%B8%9A%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Telesquare路由器RCE(CVE-2024-29269)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/Telesquare%E8%B7%AF%E7%94%B1%E5%99%A8RCE(CVE-2024-29269).md
物业专项维修资金管理系统漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%89%A9%E4%B8%9A%E4%B8%93%E9%A1%B9%E7%BB%B4%E4%BF%AE%E8%B5%84%E9%87%91%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E7%89%A9%E4%B8%9A%E4%B8%93%E9%A1%B9%E7%BB%B4%E4%BF%AE%E8%B5%84%E9%87%91%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E6%BC%8F%E6%B4%9E.md
用友NC-ActionServlet存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-ActionServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
潍微科技-水务信息管理平台ChangePwd接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%BD%8D%E5%BE%AE%E7%A7%91%E6%8A%80/%E6%BD%8D%E5%BE%AE%E7%A7%91%E6%8A%80-%E6%B0%B4%E5%8A%A1%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0ChangePwd%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
OpenMetadata命令执行(CVE-2024-28255)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OpenMetadata/OpenMetadata%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C(CVE-2024-28255).md
魔方网表mailupdate.jsp接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%AD%94%E6%96%B9%E7%BD%91%E8%A1%A8/%E9%AD%94%E6%96%B9%E7%BD%91%E8%A1%A8mailupdate.jsp%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
奇安信VPN任意用户密码重置https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/%E5%A5%87%E5%AE%89%E4%BF%A1VPN%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE.md
润乾报表平台InputServlet存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8%E5%B9%B3%E5%8F%B0InputServlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
医院一站式后勤管理系统processApkUpload.upload存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8C%BB%E9%99%A2%E4%B8%80%E7%AB%99%E5%BC%8F%E5%90%8E%E5%8B%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%8C%BB%E9%99%A2%E4%B8%80%E7%AB%99%E5%BC%8F%E5%90%8E%E5%8B%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FprocessApkUpload.upload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240410-新增漏洞
泛微E-Mobile-client.do存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Mobile-client.do%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
致远互联-OA前台fileUpload.do存在绕过文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94-OA%E5%89%8D%E5%8F%B0fileUpload.do%E5%AD%98%E5%9C%A8%E7%BB%95%E8%BF%87%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
宏景eHR人力资源管理软件showmediainfo存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E8%BD%AF%E4%BB%B6showmediainfo%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC接口PaWfm存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3PaWfm%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC接口ConfigResourceServlet存在反序列漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3ConfigResourceServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md
用友NC-runStateServlet接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-runStateServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC-workflowImageServlet接口存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-workflowImageServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
畅捷通TPlus-KeyInfoList.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%95%85%E6%8D%B7%E9%80%9ATPlus-KeyInfoList.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
畅捷通TPlus-App_Code.ashx存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%95%85%E6%8D%B7%E9%80%9ATPlus-App_Code.ashx%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
H3C_magic_R100路由器的UDPserver中存在命令执行漏洞(CVE-2022-34598)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C_magic_R100%E8%B7%AF%E7%94%B1%E5%99%A8%E7%9A%84UDPserver%E4%B8%AD%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2022-34598).md
用友NC_saveImageServlet接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC_saveImageServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微e-cology-ProcessOverRequestByXml接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology-ProcessOverRequestByXml%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友crm-swfupload接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8Bcrm-swfupload%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240406-新增漏洞
用友U9-PatchFile.asmx接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU9-PatchFile.asmx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud_importhttpscer接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud_importhttpscer%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
亿赛通DecryptApplicationService2接口任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9ADecryptApplicationService2%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
亿赛通update接口sql注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9Aupdate%E6%8E%A5%E5%8F%A3sql%E6%B3%A8%E5%85%A5.md
用友U8cloud接口MeasureQueryByToolAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8cloud%E6%8E%A5%E5%8F%A3MeasureQueryByToolAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
浙大恩特客户资源管理系统-RegulatePriceAction存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-RegulatePriceAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
科荣AIO-ReadFile存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%8D%A3AIO/%E7%A7%91%E8%8D%A3AIO-ReadFile%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
东方通TongWeb-selectApp.jsp存在任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E6%96%B9%E9%80%9A/%E4%B8%9C%E6%96%B9%E9%80%9ATongWeb-selectApp.jsp%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
WordPress-js-support-ticket存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-js-support-ticket%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
WordPress-thimpress_hotel_booking存在代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress-thimpress_hotel_booking%E5%AD%98%E5%9C%A8%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE-wf_printnum.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE-wf_printnum.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8cloud-ExportUfoFormatAction存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8cloud-ExportUfoFormatAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
JeePlus低代码开发平台存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
润乾报表InputServlet接口存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8/%E6%B6%A6%E4%B9%BE%E6%8A%A5%E8%A1%A8InputServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
D-Link-NAS(CVE-2024-3272&&CVE-2024-3273)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-Link-NAS(CVE-2024-3272&&CVE-2024-3273).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240329-新增漏洞
泛微E-Office10版本小于v10.0_20240222存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office10%E7%89%88%E6%9C%AC%E5%B0%8F%E4%BA%8Ev10.0_20240222%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友NC接口saveXmlToFIleServlet存在文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3saveXmlToFIleServlet%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
TP-Link-ER7206存在命令注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/TP-Link-ER7206%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
JumpServer(CVE-2024-29201)远程代码执行漏洞&(CVE-2024-29202)Jinin2模板注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JumpServer/JumpServer(CVE-2024-29201)%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E&(CVE-2024-29202)Jinin2%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud接口FileManageServlet存在反序列漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E6%8E%A5%E5%8F%A3FileManageServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud接口ServiceDispatcherServlet存在反序列漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E6%8E%A5%E5%8F%A3ServiceDispatcherServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md
泛微e-cology接口getLabelByModule存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology%E6%8E%A5%E5%8F%A3getLabelByModule%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
WordPress_LayerSlider插件SQL注入漏洞(CVE-2024-2879)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress_LayerSlider%E6%8F%92%E4%BB%B6SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-2879).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240328-新增漏洞
通天星-CMSV6-inspect_file-upload存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%80%9A%E5%A4%A9%E6%98%9F-CMSV6-inspect_file-upload%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友U8-Cloud接口FileServlet存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E6%8E%A5%E5%8F%A3FileServlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
联达OA-UpLoadFile.aspx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BE%BEOA/%E8%81%94%E8%BE%BEOA-UpLoadFile.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
协达OA系统绕过登录认证登陆后台https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8F%E8%BE%BEOA/%E5%8D%8F%E8%BE%BEOA%E7%B3%BB%E7%BB%9F%E7%BB%95%E8%BF%87%E7%99%BB%E5%BD%95%E8%AE%A4%E8%AF%81%E7%99%BB%E9%99%86%E5%90%8E%E5%8F%B0.md
用友U8-nc.bs.sm.login2.RegisterServlet存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-nc.bs.sm.login2.RegisterServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金石工程项目管理系统TianBaoJiLu.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E7%9F%B3%E5%B7%A5%E7%A8%8B%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E9%87%91%E7%9F%B3%E5%B7%A5%E7%A8%8B%E9%A1%B9%E7%9B%AE%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FTianBaoJiLu.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
易宝OA-BasicService.asmx存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA-BasicService.asmx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
WordPress Automatic Plugin任意文件下载漏洞(CVE-2024-27954)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%20Automatic%20Plugin%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E(CVE-2024-27954).md
商混ERP-DictionaryEdit.aspxSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%95%86%E6%B7%B7ERP/%E5%95%86%E6%B7%B7ERP-DictionaryEdit.aspxSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240327-新增漏洞
Adobe-ColdFusion任意文件读取漏洞CVE-2024-20767https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Adobe%20ColdFusion/Adobe-ColdFusion%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9ECVE-2024-20767.md
Fortinet-SSL-VPN-CVE-2024-21762https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Fortinet/Fortinet-SSL-VPN-CVE-2024-21762.md
omfyUI follow_symlinks文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/omfyUI/omfyUI%20follow_symlinks%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Fortra FileCatalyst Workflow远程代码执行漏漏洞(CVE-2024-25153)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Fortra/Fortra%20FileCatalyst%20Workflow%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%BC%8F%E6%B4%9E(CVE-2024-25153).md
联达OA uploadLogo.aspx存在任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BE%BEOA/%E8%81%94%E8%BE%BEOA%20uploadLogo.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
网络验证系统getInfo参数存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E7%BB%9C%E9%AA%8C%E8%AF%81%E7%B3%BB/%E7%BD%91%E7%BB%9C%E9%AA%8C%E8%AF%81%E7%B3%BB%E7%BB%9FgetInfo%E5%8F%82%E6%95%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
致远OA-ucpcLogin密码重置漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA-ucpcLogin%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md
Cobbler存在远程命令执行漏洞(CVE-2021-40323)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Cobbler/Cobbler%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2021-40323).md
锐捷网络无线AC命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7%E7%BD%91%E7%BB%9C%E6%97%A0%E7%BA%BFAC%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240324-新增漏洞
飞企互联-FE企业运营管理平台uploadAttachmentServlet存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0uploadAttachmentServlet%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Netgear路由器boardDataWW.php存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/Netgear%E8%B7%AF%E7%94%B1%E5%99%A8boardDataWW.php%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
瑞友应用虚拟化系统-RAPAgent存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%91%9E%E5%8F%8B%E5%A4%A9%E7%BF%BC%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9F/%E7%91%9E%E5%8F%8B%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9F-RAPAgent%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1%E6%8C%87%E6%8C%A5%E8%B0%83%E5%BA%A6%E5%B9%B3%E5%8F%B0get_extension_yl.php%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友畅捷通RRATableController存在反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%95%85%E6%8D%B7%E9%80%9ARRATableController%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
用友时空KSOA-imagefield接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA-imagefield%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
F-logic_DataCube3存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/F%20logic%20DataCube3/F-logic_DataCube3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
泛微getE9DevelopAllNameValue2接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEgetE9DevelopAllNameValue2%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
大华DSS城市安防监控平台Struct2-045命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EDSS%E5%9F%8E%E5%B8%82%E5%AE%89%E9%98%B2%E7%9B%91%E6%8E%A7%E5%B9%B3%E5%8F%B0Struct2-045%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240320-新增漏洞
飞鱼星上网行为管理系统企业版前台RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E9%B1%BC%E6%98%9F/%E9%A3%9E%E9%B1%BC%E6%98%9F%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BC%81%E4%B8%9A%E7%89%88%E5%89%8D%E5%8F%B0RCE.md
WordPress_Wholesale_Market插件存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress_Wholesale_Market%E6%8F%92%E4%BB%B6%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
万户ezOFFICE-contract_gd.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezOFFICE-contract_gd.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景eHR-report_org_collect_tree.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR-report_org_collect_tree.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
正方教学管理信息服务平台ReportServer存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%AD%A3%E6%96%B9/%E6%AD%A3%E6%96%B9%E6%95%99%E5%AD%A6%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0ReportServer%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金和OA-C6-IncentivePlanFulfill.aspx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA-C6-IncentivePlanFulfill.aspx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华DSS数字监控系统attachment_clearTempFile.action存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EDSS%E6%95%B0%E5%AD%97%E7%9B%91%E6%8E%A7%E7%B3%BB%E7%BB%9Fattachment_clearTempFile.action%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NCCloud系统runScript存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNCCloud%E7%B3%BB%E7%BB%9FrunScript%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240314-新增漏洞
亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A-%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E9%98%B2%E6%8A%A4(DLP)ClientAjax%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统DecryptApplication存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FDecryptApplication%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金和OA_jc6_viewConTemplate.action存在FreeMarker模板注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_jc6_viewConTemplate.action%E5%AD%98%E5%9C%A8FreeMarker%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8_Cloud-base64存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8_Cloud-base64%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华智慧园区综合管理平台pageJson存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0pageJson%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金蝶云-星空ServiceGateway反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6%E4%BA%91-%E6%98%9F%E7%A9%BAServiceGateway%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
友点建站系统image_upload.php存在文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8F%8B%E7%82%B9%E5%BB%BA%E7%AB%99%E7%B3%BB%E7%BB%9F/%E5%8F%8B%E7%82%B9%E5%BB%BA%E7%AB%99%E7%B3%BB%E7%BB%9Fimage_upload.php%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
D-Link_DAR-8000操作系统命令注入漏洞(CVE-2023-4542)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-Link_DAR-8000%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2023-4542).md
D-Link_DAR-8000-10上网行为审计网关任意文件上传漏洞(CVE-2023-5154)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/D-Link/D-Link_DAR-8000-10%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E5%AE%A1%E8%AE%A1%E7%BD%91%E5%85%B3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E(CVE-2023-5154).md
中成科信票务管理平台任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%B8%AD%E6%88%90%E7%A7%91%E4%BF%A1%E7%A5%A8%E5%8A%A1%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Springblade默认密钥可伪造凭据https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/Springblade%E9%BB%98%E8%AE%A4%E5%AF%86%E9%92%A5%E5%8F%AF%E4%BC%AA%E9%80%A0%E5%87%AD%E6%8D%AE.md
CERIO-DT系列路由器Save.cgi接口存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/CERIO-DT%E7%B3%BB%E5%88%97%E8%B7%AF%E7%94%B1%E5%99%A8Save.cgi%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240312-新增漏洞
宏景HCM-codesettree接口存在SQL注入漏洞 https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFHCM-codesettree%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
SpringBlade blade-log存在SQL 注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/SpringBlade%20blade-log%E5%AD%98%E5%9C%A8SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
宏景HCM-downlawbase接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFHCM-downlawbase%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
天问物业ERP系统docfileDownLoad.aspx存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E9%97%AE%E7%89%A9%E4%B8%9AERP%E7%B3%BB%E7%BB%9FdocfileDownLoad.aspx%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
H3C 用户自助服务平台 dynamiccontent.properties.xhtml存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C%20%E7%94%A8%E6%88%B7%E8%87%AA%E5%8A%A9%E6%9C%8D%E5%8A%A1%E5%B9%B3%E5%8F%B0%20dynamiccontent.properties.xhtml%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
网康科技 NS-ASG 应用安全网关 SQL注入漏洞(CVE-2024-2330)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80%20NS-ASG%20%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-2330).md
大华智慧园区clientServer接口SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BAclientServer%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华智慧园区getNewStaypointDetailQuery接口SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BAgetNewStaypointDetailQuery%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网康NS-ASG应用安全网关singlelogin.php存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3singlelogin.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
网康科技NS-ASG应用安全网关list_ipAddressPolicy.php存在SQL注入漏洞(CVE-2024-2022)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80/%E7%BD%91%E5%BA%B7%E7%A7%91%E6%8A%80NS-ASG%E5%BA%94%E7%94%A8%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3list_ipAddressPolicy.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-2022).md
用友NC-saveDoc.ajax存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-saveDoc.ajax%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统NavigationAjax接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FNavigationAjax%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
海康威视综合安防系统detection接口存在RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%B3%BB%E7%BB%9Fdetection%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240305-新增漏洞
H3C-校园网自助服务系统flexfileupload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-%E6%A0%A1%E5%9B%AD%E7%BD%91%E8%87%AA%E5%8A%A9%E6%9C%8D%E5%8A%A1%E7%B3%BB%E7%BB%9Fflexfileupload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
绿盟日志审计系统存在命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BB%BF%E7%9B%9F/%E7%BB%BF%E7%9B%9F%E6%97%A5%E5%BF%97%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
JetBrains TeamCity 身份验证绕过漏洞(CVE-2024-27198)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JetBrains/JetBrains%20TeamCity%20%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E(CVE-2024-27198).md
H3C-SecParh堡垒机任意用户登录漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C-SecParh%E5%A0%A1%E5%9E%92%E6%9C%BA%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.md
红帆ioffice-udfGetDocStep.asmx存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BA%A2%E5%B8%86OA/%E7%BA%A2%E5%B8%86ioffice-udfGetDocStep.asmx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
致远前台任意用户密码修改https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E4%BF%AE%E6%94%B9.md
JEEVMS仓库管理系统任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JEEVMS%E4%BB%93%E5%BA%93%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/JEEVMS%E4%BB%93%E5%BA%93%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
海康威视iVMS综合安防系统resourceOperations接口任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86iVMS%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%B3%BB%E7%BB%9FresourceOperations%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
WordPress插件Bricks Builder存在RCE漏洞(CVE-2024-25600)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6Bricks%20Builder%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E(CVE-2024-25600).md
大华EIMS-capture_handle接口远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EEIMS-capture_handle%E6%8E%A5%E5%8F%A3%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
帮管客CRM-jiliyu接口存在SQL漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B8%AE%E7%AE%A1%E5%AE%A2CRM/%E5%B8%AE%E7%AE%A1%E5%AE%A2CRM-jiliyu%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240301-新增漏洞
RG-UAC锐捷统一上网行为管理与审计系统存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/RG-UAC%E9%94%90%E6%8D%B7%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E4%B8%8E%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
RUOYI-v4.7.8存在远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/RuoYi/RUOYI-v4.7.8%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
西软云XMS-futurehotel-query接口存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%A5%BF%E8%BD%AF%E4%BA%91/%E8%A5%BF%E8%BD%AF%E4%BA%91XMS-futurehotel-query%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
西软云XMS-futurehotel-operate接口存在XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%A5%BF%E8%BD%AF%E4%BA%91/%E8%A5%BF%E8%BD%AF%E4%BA%91XMS-futurehotel-operate%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md
宏景eHR-HCM-DisplayExcelCustomReport接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AFeHR-HCM-DisplayExcelCustomReport%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友U9-UMWebService.asmx存在文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU9-UMWebService.asmx%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友U8 Cloud-KeyWordReportQuery存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8%20Cloud-KeyWordReportQuery%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8 Cloud-ArchiveVerify存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8%20Cloud-ArchiveVerify%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
易宝OA系统DownloadFile接口存在文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA%E7%B3%BB%E7%BB%9FDownloadFile%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
浙大恩特客户资源管理系统-purchaseaction.entphone接口存在SQL漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F-purchaseaction.entphone%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%BC%8F%E6%B4%9E.md
惠尔顿-网络安全审计系统存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%83%A0%E5%B0%94%E9%A1%BF-%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F/%E6%83%A0%E5%B0%94%E9%A1%BF-%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
蓝凌EIS智慧协同平台rpt_listreport_definefield.aspx接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0rpt_listreport_definefield.aspx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240228-新增漏洞
鸿运(通天星CMSV6车载)主动安全监控云平台存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E5%A4%A9%E6%98%9F/%E9%B8%BF%E8%BF%90(%E9%80%9A%E5%A4%A9%E6%98%9FCMSV6%E8%BD%A6%E8%BD%BD)%E4%B8%BB%E5%8A%A8%E5%AE%89%E5%85%A8%E7%9B%91%E6%8E%A7%E4%BA%91%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
万户OA-RhinoScriptEngineService命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA-RhinoScriptEngineService%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
宏景 DisplayFiles任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%8F%E6%99%AFOA/%E5%AE%8F%E6%99%AF%20DisplayFiles%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
蓝凌OA-WechatLoginHelper.do存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8COA-WechatLoginHelper.do%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友U8-OA协同工作系统doUpload.jsp任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-OA%E5%8D%8F%E5%90%8C%E5%B7%A5%E4%BD%9C%E7%B3%BB%E7%BB%9FdoUpload.jsp%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
aiohttp存在目录遍历漏洞(CVE-2024-23334)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/aiohttp/aiohttp%E5%AD%98%E5%9C%A8%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E(CVE-2024-23334).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240217-新增漏洞
宝塔最新未授权访问漏洞及sql注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%9D%E5%A1%94/%E5%AE%9D%E5%A1%94%E6%9C%80%E6%96%B0%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%E5%8F%8Asql%E6%B3%A8%E5%85%A5.md
金盘移动图书馆系统存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E7%9B%98/%E9%87%91%E7%9B%98%E7%A7%BB%E5%8A%A8%E5%9B%BE%E4%B9%A6%E9%A6%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Panalog大数据日志审计系统libres_syn_delete.php存在命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Panalog/Panalog%E5%A4%A7%E6%95%B0%E6%8D%AE%E6%97%A5%E5%BF%97%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9Flibres_syn_delete.php%E5%AD%98%E5%9C%A8%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
WAGO系统远程代码执行漏洞(CVE-2023-1698)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WAGO/WAGO%E7%B3%BB%E7%BB%9F%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-1698).md
山石网科云鉴存在前台任意命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B1%B1%E7%9F%B3%E7%BD%91%E7%A7%91%E4%BA%91%E9%89%B4/%E5%B1%B1%E7%9F%B3%E7%BD%91%E7%A7%91%E4%BA%91%E9%89%B4%E5%AD%98%E5%9C%A8%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#2024025-新增漏洞
天翼应用虚拟化系统sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E7%BF%BC%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9F/%E5%A4%A9%E7%BF%BC%E5%BA%94%E7%94%A8%E8%99%9A%E6%8B%9F%E5%8C%96%E7%B3%BB%E7%BB%9Fsql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
LinkWeChat任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/LinkWeChat/LinkWeChat%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Weblogic远程代码执行(CVE-2024-20931)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Weblogic/Weblogic%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C(CVE-2024-20931).md
亿赛通-dataSearch.jsp-SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A-dataSearch.jsp-SQL%E6%B3%A8%E5%85%A5.md
https://patch-diff.githubusercontent.com/pygopher/POC#2024022-新增漏洞
亿赛通电子文档安全管理系统 UploadFileToCatalog SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20UploadFileToCatalog%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统GetValidateLoginUserService接口存在XStream反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGetValidateLoginUserService%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XStream%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统UploadFileList任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FUploadFileList%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
大华智慧园区综合管理平台bitmap接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0bitmap%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
飞企互联-FE企业运营管理平台publicData.jsp存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0publicData.jsp%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240126-新增漏洞
Jenkins任意文件读取漏洞(CVE-2024-23897)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Jenkins/Jenkins%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-23897).md
SpringBlade export-user SQL 注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpringBlade/SpringBlade%20export-user%20SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
万户OA text2Html接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA%20text2Html%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
亿赛通电子文档安全管理系统hiddenWatermark文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FhiddenWatermark%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友系统-U9企业版存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%B3%BB%E7%BB%9F-U9%E4%BC%81%E4%B8%9A%E7%89%88%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
广联达-linkworks-gwgdwebservice存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BE-linkworks-gwgdwebservice%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
远秋医学培训系统未授权查看密码https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%BF%9C%E7%A7%8B%E5%8C%BB%E5%AD%A6%E5%9F%B9%E8%AE%AD%E7%B3%BB%E7%BB%9F/%E8%BF%9C%E7%A7%8B%E5%8C%BB%E5%AD%A6%E5%9F%B9%E8%AE%AD%E7%B3%BB%E7%BB%9F%E6%9C%AA%E6%8E%88%E6%9D%83%E6%9F%A5%E7%9C%8B%E5%AF%86%E7%A0%81.md
联软安全数据交换系统任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%81%94%E8%BD%AF/%E8%81%94%E8%BD%AF%E5%AE%89%E5%85%A8%E6%95%B0%E6%8D%AE%E4%BA%A4%E6%8D%A2%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
Apache Tomcat存在信息泄露漏洞( CVE-2024-21733)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Tomcat%E5%AD%98%E5%9C%A8%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E(%20CVE-2024-21733).md
https://patch-diff.githubusercontent.com/pygopher/POC#20240117-新增漏洞
Yearning_front任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Yearning/Yearning_front%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
云网OA8.6存在fastjson反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E7%BD%91OA/%E4%BA%91%E7%BD%91OA8.6%E5%AD%98%E5%9C%A8fastjson%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
Apache Dubbo-admin-authorized-bypass (CNVD-2023-96546)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Dubbo-admin-authorized-bypass%20(CNVD-2023-96546).md
先锋WEB燃气收费系统文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%88%E9%94%8BWEB%E7%87%83%E6%B0%94%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9F/%E5%85%88%E9%94%8BWEB%E7%87%83%E6%B0%94%E6%94%B6%E8%B4%B9%E7%B3%BB%E7%BB%9F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
MRCMS3.0任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/MRCMS/MRCMS3.0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
奇安信天擎rptsvr任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/%E5%A5%87%E5%AE%89%E4%BF%A1%E5%A4%A9%E6%93%8Erptsvr%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
用友GRP-U8-SelectDMJE.jsp_SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-SelectDMJE.jsp_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Ivanti_Connect_Secure远程命令注入漏洞(CVE-2024-21887)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ivanti/Ivanti_Connect_Secure%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-21887).md
天擎终端安全管理系统YII_CSRF_TOKEN远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/%E5%A4%A9%E6%93%8E%E7%BB%88%E7%AB%AF%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FYII_CSRF_TOKEN%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友移动系统管理getFileLocal接口存在任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%A7%BB%E5%8A%A8%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86getFileLocal%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
网神SecGate 3600 防火墙sys_hand_upfile 任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E7%A5%9E/%E7%BD%91%E7%A5%9ESecGate%203600%20%E9%98%B2%E7%81%AB%E5%A2%99sys_hand_upfile%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Atlassian Confluence 远程代码执行漏洞(CVE-2023-22527)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Confluence/Atlassian%20Confluence%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-22527).md
Laykefu客服系统任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Laykefu%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F/Laykefu%E5%AE%A2%E6%9C%8D%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240112-新增漏洞
GitLab任意用户密码重置漏洞(CVE-2023-7028)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/GitLab/GitLab%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E(CVE-2023-7028).md
SpiderFlow爬虫平台远程命令执行漏洞(CVE-2024-0195)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SpiderFlow%E7%88%AC%E8%99%AB%E5%B9%B3%E5%8F%B0/SpiderFlow%E7%88%AC%E8%99%AB%E5%B9%B3%E5%8F%B0%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-0195).md
亿赛通电子文档安全管理系统dump接口存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fdump%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金和OA_SAP_B1Config.aspx未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_SAP_B1Config.aspx%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
致远OA_getAjaxDataServlet接口存在任XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA_getAjaxDataServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BBXXE%E6%BC%8F%E6%B4%9E.md
金和OA_jc6_ntko-upload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_jc6_ntko-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
蓝凌EIS智慧协同平台多个接口SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0%E5%A4%9A%E4%B8%AA%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5.md
金和OA_CarCardInfo.aspx_SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_CarCardInfo.aspx_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金和OA_MailTemplates.aspx_SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_MailTemplates.aspx_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
金和OA_upload_json.asp存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_upload_json.asp%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
金和OA_uploadfileeditorsave接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_uploadfileeditorsave%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Ncast盈可视高清智能录播系统存在RCE漏洞(CVE-2024-0305)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F/Ncast%E7%9B%88%E5%8F%AF%E8%A7%86%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8RCE%E6%BC%8F%E6%B4%9E(CVE-2024-0305).md
金和OA_jc6_Upload任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_jc6_Upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
Apache_Solr环境变量信息泄漏漏洞(CVE-2023-50290)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache_Solr%E7%8E%AF%E5%A2%83%E5%8F%98%E9%87%8F%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E(CVE-2023-50290).md
浙大恩特客户资源管理系统crmbasicaction任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9Fcrmbasicaction%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240109-新增漏洞
金和OA_HomeService.asmxSQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA_HomeService.asmxSQL%E6%B3%A8%E5%85%A5.md
用友移动管理平台uploadIcon任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%E7%A7%BB%E5%8A%A8%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0uploadIcon%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
捷诚管理信息系统sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%8D%B7%E8%AF%9A%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9F/%E6%8D%B7%E8%AF%9A%E7%AE%A1%E7%90%86%E4%BF%A1%E6%81%AF%E7%B3%BB%E7%BB%9Fsql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
奇安信网康下一代防火墙directdata存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/%E5%A5%87%E5%AE%89%E4%BF%A1%E7%BD%91%E5%BA%B7%E4%B8%8B%E4%B8%80%E4%BB%A3%E9%98%B2%E7%81%AB%E5%A2%99directdata%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240105-新增漏洞
用友NC_CLOUD_smartweb2.RPC.d_XML外部实体注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC_CLOUD_smartweb2.RPC.d_XML%E5%A4%96%E9%83%A8%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5.md
IDocView_qJvqhFt接口任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/iDocView/IDocView_qJvqhFt%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
⻜企互联loginService任意登录https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E2%BB%9C%E4%BC%81%E4%BA%92%E8%81%94loginService%E4%BB%BB%E6%84%8F%E7%99%BB%E5%BD%95.md
全程云OA__ajax.ashxSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%85%A8%E7%A8%8B%E4%BA%91OA/%E5%85%A8%E7%A8%8B%E4%BA%91OA__ajax.ashxSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微移动管理平台lang2sql接口任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE%E7%A7%BB%E5%8A%A8%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0lang2sql%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
广联达OA任意用户登录https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95.md
广联达OA前台任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E8%81%94%E8%BE%BEOA/%E5%B9%BF%E8%81%94%E8%BE%BEOA%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
金蝶EAS_pdfviewlocal任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6EAS_pdfviewlocal%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
PbootCMS全版本后台通杀任意代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/PbootCMS/PbootCMS%E5%85%A8%E7%89%88%E6%9C%AC%E5%90%8E%E5%8F%B0%E9%80%9A%E6%9D%80%E4%BB%BB%E6%84%8F%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20240103-新增漏洞
天融信TOPSEC_maincgi.cgi远程命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E8%9E%8D%E4%BF%A1/%E5%A4%A9%E8%9E%8D%E4%BF%A1TOPSEC_maincgi.cgi%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
天融信TOPSEC_static_convert远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E8%9E%8D%E4%BF%A1/%E5%A4%A9%E8%9E%8D%E4%BF%A1TOPSEC_static_convert%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
用友CRM系统reservationcomplete.php存在逻辑漏洞直接登录后台https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BCRM%E7%B3%BB%E7%BB%9Freservationcomplete.php%E5%AD%98%E5%9C%A8%E9%80%BB%E8%BE%91%E6%BC%8F%E6%B4%9E%E7%9B%B4%E6%8E%A5%E7%99%BB%E5%BD%95%E5%90%8E%E5%8F%B0.md
亿赛通电子文档uploadFile接口文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E4%BA%BF%E8%B5%9B%E9%80%9A%E7%94%B5%E5%AD%90%E6%96%87%E6%A1%A3uploadFile%E6%8E%A5%E5%8F%A3%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231231-新增漏洞
OfficeWeb365_任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OfficeWeb365/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
东华医疗协同办公系统反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
东华医疗协同办公系统文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F/%E4%B8%9C%E5%8D%8E%E5%8C%BB%E7%96%97%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
飞企互联-FE企业运营管理平台登录绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94-FE%E4%BC%81%E4%B8%9A%E8%BF%90%E8%90%A5%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E7%99%BB%E5%BD%95%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
飞企互联Ognl表达式注入导致RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94/%E9%A3%9E%E4%BC%81%E4%BA%92%E8%81%94Ognl%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E5%AF%BC%E8%87%B4RCE.md
西软云XMS反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%A5%BF%E8%BD%AF%E4%BA%91/%E8%A5%BF%E8%BD%AF%E4%BA%91XMS%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
用友U8_cloud_KeyWordDetailReportQuery_SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8_cloud_KeyWordDetailReportQuery_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
用友NC_Cloud_soapFormat.ajax接口存在XXEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC_Cloud_soapFormat.ajax%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8XXE.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231228-新增漏洞
wordpress listingo 文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/wordpress%20listingo%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Apache OFBiz 身份验证绕过漏洞 (CVE-2023-51467)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20OFBiz%20%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20(CVE-2023-51467).md
福建科立讯通信有限公司指挥调度管理平台RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1/%E7%A6%8F%E5%BB%BA%E7%A7%91%E7%AB%8B%E8%AE%AF%E9%80%9A%E4%BF%A1%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8%E6%8C%87%E6%8C%A5%E8%B0%83%E5%BA%A6%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0RCE.md
海康威视-综合安防管理平台-files-文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86-%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0-files-%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
Apache OFBiz SSRF && 任意配置读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20OFBiz%20SSRF%20&&%20%E4%BB%BB%E6%84%8F%E9%85%8D%E7%BD%AE%E8%AF%BB%E5%8F%96.md
Apache Dubbo 反序列化漏洞(CVE-2023-29234)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Dubbo%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2023-29234%EF%BC%89.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231226-新增漏洞
大华DSS itcBulletin SQL 注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8EDSS%20itcBulletin%20SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
湖南建研-检测系统 admintool 任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F/%E6%B9%96%E5%8D%97%E5%BB%BA%E7%A0%94-%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%20admintool%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
OpenSSH ProxyCommand命令注入漏洞 (CVE-2023-51385)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/OpenSSH/OpenSSH%20ProxyCommand%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20(CVE-2023-51385).md
Salia PLCC cPH2 远程命令执行漏洞(CVE-2023-46359)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Salia/Salia%20PLCC%20cPH2%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-46359).md
金蝶Apusic应用服务器loadTree JNDI注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6Apusic%E5%BA%94%E7%94%A8%E6%9C%8D%E5%8A%A1%E5%99%A8loadTree%20JNDI%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
科荣 AIO任意文件上传-目录遍历-任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%A7%91%E8%8D%A3AIO/%E7%A7%91%E8%8D%A3%20AIO%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0-%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86-%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Secnet安网 智能AC管理系统 actpt_5g 信息泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Secnet%E5%AE%89%E7%BD%91%E6%99%BA%E8%83%BDAC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/Secnet%E5%AE%89%E7%BD%91%20%E6%99%BA%E8%83%BDAC%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20actpt_5g%20%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md
海康威视安全接入网关任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E5%AE%89%E5%85%A8%E6%8E%A5%E5%85%A5%E7%BD%91%E5%85%B3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
浙江宇视isc网络视频录像机LogReport.php存在远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E6%B1%9F%E5%AE%87%E8%A7%86/%E6%B5%99%E6%B1%9F%E5%AE%87%E8%A7%86isc%E7%BD%91%E7%BB%9C%E8%A7%86%E9%A2%91%E5%BD%95%E5%83%8F%E6%9C%BALogReport.php%E5%AD%98%E5%9C%A8%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
海翔ERP SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E7%BF%94ERP/%E6%B5%B7%E7%BF%94ERP%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
脸爱云 一脸通智慧管理平台任意用户添加漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%84%B8%E7%88%B1%E4%BA%91%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E8%84%B8%E7%88%B1%E4%BA%91%20%E4%B8%80%E8%84%B8%E9%80%9A%E6%99%BA%E6%85%A7%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md
安恒明御安全网关远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%89%E6%81%92/%E5%AE%89%E6%81%92%E6%98%8E%E5%BE%A1%E5%AE%89%E5%85%A8%E7%BD%91%E5%85%B3%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231223-新增漏洞
avcon综合管理平台SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/AVCON/avcon%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
致远互联FE协作办公平台editflow_manager存在sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E4%BA%92%E8%81%94FE%E5%8D%8F%E4%BD%9C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0editflow_manager%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
海康威视CVE-2023-6895 IP网络对讲广播系统远程命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86CVE-2023-6895%20IP%E7%BD%91%E7%BB%9C%E5%AF%B9%E8%AE%B2%E5%B9%BF%E6%92%AD%E7%B3%BB%E7%BB%9F%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
铭飞CMS list接口存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%93%AD%E9%A3%9E/%E9%93%AD%E9%A3%9ECMS%20list%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
海康威视IP网络对讲广播系统任意文件下载漏洞CVE-2023-6893https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86IP%E7%BD%91%E7%BB%9C%E5%AF%B9%E8%AE%B2%E5%B9%BF%E6%92%AD%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9ECVE-2023-6893.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231217-新增漏洞
大华智能物联综合管理平台justForTest用户登录漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E8%83%BD%E7%89%A9%E8%81%94%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0justForTest%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.md
CloudPanel RCE漏洞 CVE-2023-35885https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/CloudPanel/CloudPanel%20RCE%E6%BC%8F%E6%B4%9E%20CVE-2023-35885.md
Smartbi 内置用户登陆绕过https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Smartbi/Smartbi%20%E5%86%85%E7%BD%AE%E7%94%A8%E6%88%B7%E7%99%BB%E9%99%86%E7%BB%95%E8%BF%87.md
金和OA jc6 clobfield SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA%20jc6%20clobfield%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
EasyCVR 视频管理平台存在用户信息泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/EasyCVR%20%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E7%94%A8%E6%88%B7%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md
用友CRM 任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BCRM%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金蝶星空云K3Cloud反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6%E6%98%9F%E7%A9%BA%E4%BA%91K3Cloud%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231215-新增漏洞
万户ezoffice wpsservlet任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7ezoffice%20wpsservlet%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
万户 ezOFFICE DocumentEdit.jsp SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7%20ezOFFICE%20DocumentEdit.jsp%20SQL%E6%B3%A8%E5%85%A5.md
用友 NC uapws wsdl XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20NC%20uapws%20wsdl%20XXE%E6%BC%8F%E6%B4%9E.md
iDocView upload接口任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/iDocView/iDocView%20upload%E6%8E%A5%E5%8F%A3%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
Wordpress Backup Migration plugin 代码执行漏洞(CVE-2023-6553)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WordPress/Wordpress%20Backup%20Migration%20plugin%20%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-6553).md
https://patch-diff.githubusercontent.com/pygopher/POC#20231214-新增漏洞
泛微云桥 e-Bridge addTaste接口SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE%E4%BA%91%E6%A1%A5%20e-Bridge%20addTaste%E6%8E%A5%E5%8F%A3SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Tenda路由器账号密码泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Tenda/Tenda%E8%B7%AF%E7%94%B1%E5%99%A8%E8%B4%A6%E5%8F%B7%E5%AF%86%E7%A0%81%E6%B3%84%E9%9C%B2.md
思福迪运维安全管理系统RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%80%9D%E7%A6%8F%E8%BF%AA%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%80%9D%E7%A6%8F%E8%BF%AA%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FRCE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231211-新增漏洞
Apache Struts2 CVE-2023-50164https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Struts2%20CVE-2023-50164.md
蓝凌EKP前台授权绕过导致文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEKP%E5%89%8D%E5%8F%B0%E6%8E%88%E6%9D%83%E7%BB%95%E8%BF%87%E5%AF%BC%E8%87%B4%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
通达OA header身份认证绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA%20header%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231208-新增漏洞
Dedecms v5.7.111前台tags.php SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/dede/Dedecms%20v5.7.111%E5%89%8D%E5%8F%B0tags.php%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
云时空社会化商业ERP任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E6%97%B6%E7%A9%BA/%E4%BA%91%E6%97%B6%E7%A9%BA%E7%A4%BE%E4%BC%9A%E5%8C%96%E5%95%86%E4%B8%9AERP%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
奥威亚视频云平台VideoCover.aspx接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%A5%E5%A8%81%E4%BA%9A%E8%A7%86%E9%A2%91%E4%BA%91%E5%B9%B3%E5%8F%B0/%E5%A5%A5%E5%A8%81%E4%BA%9A%E8%A7%86%E9%A2%91%E4%BA%91%E5%B9%B3%E5%8F%B0VideoCover.aspx%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231207-新增漏洞
WeiPHP存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WeiPHP/WeiPHP%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
Apache Ofbiz XML-RPC RCE漏洞-CVE-2023-49070https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Ofbiz%20XML-RPC%20RCE%E6%BC%8F%E6%B4%9E-CVE-2023-49070.md
多个防火墙产品RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%98%B2%E7%81%AB%E5%A2%99%E4%BA%A7%E5%93%81/%E5%A4%9A%E4%B8%AA%E9%98%B2%E7%81%AB%E5%A2%99%E4%BA%A7%E5%93%81RCE.md
金蝶Apusic应用服务器任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6Apusic%E5%BA%94%E7%94%A8%E6%9C%8D%E5%8A%A1%E5%99%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231205-新增漏洞
速达软件全系产品存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9F%E8%BE%BE%E8%BD%AF%E4%BB%B6/%E9%80%9F%E8%BE%BE%E8%BD%AF%E4%BB%B6%E5%85%A8%E7%B3%BB%E4%BA%A7%E5%93%81%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
易思智能物流无人值守系统5.0存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E6%80%9D%E6%99%BA%E8%83%BD%E7%89%A9%E6%B5%81%E6%97%A0%E4%BA%BA%E5%80%BC%E5%AE%88%E7%B3%BB%E7%BB%9F/%E6%98%93%E6%80%9D%E6%99%BA%E8%83%BD%E7%89%A9%E6%B5%81%E6%97%A0%E4%BA%BA%E5%80%BC%E5%AE%88%E7%B3%BB%E7%BB%9F5.0%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
RuoYi4.6.0 SQL注入漏洞CVE-2023-49371https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/RuoYi/RuoYi4.6.0%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9ECVE-2023-49371.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231203-新增漏洞
智跃人力资源管理系统GenerateEntityFromTable.aspx SQL漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%99%BA%E8%B7%83%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%99%BA%E8%B7%83%E4%BA%BA%E5%8A%9B%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9FGenerateEntityFromTable.aspx%20SQL%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231130-新增漏洞
Apache-ActiveMQ-Jolokia-远程代码执行漏洞-CVE-2022-41678https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-ActiveMQ-Jolokia-%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2022-41678.md
红帆OA iorepsavexml.aspx 文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BA%A2%E5%B8%86OA/%E7%BA%A2%E5%B8%86OA%20iorepsavexml.aspx%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231129-新增漏洞
网神防火墙 app_av_import_save文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%BD%91%E7%A5%9E/%E7%BD%91%E7%A5%9E%E9%98%B2%E7%81%AB%E5%A2%99%20app_av_import_save%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
大华智慧园区管理平台任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
通达OA down.php接口存在未授权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA%20down.php%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231128-新增漏洞
新开普掌上校园服务管理平台service.action远程命令执行https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%96%B0%E5%BC%80%E6%99%AE%E6%8E%8C%E4%B8%8A%E6%A0%A1%E5%9B%AD%E6%9C%8D%E5%8A%A1%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0/%E6%96%B0%E5%BC%80%E6%99%AE%E6%8E%8C%E4%B8%8A%E6%A0%A1%E5%9B%AD%E6%9C%8D%E5%8A%A1%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0service.action%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
易宝OA ExecuteSqlForSingle SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%93%E5%AE%9DOA/%E6%98%93%E5%AE%9DOA%20ExecuteSqlForSingle%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
大华智慧园区综合管理平台 deleteFtp 远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E6%85%A7%E5%9B%AD%E5%8C%BA%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20deleteFtp%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
云匣子堡垒机fastjson漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%BA%91%E5%8C%A3%E5%AD%90%E5%A0%A1%E5%9E%92%E6%9C%BA/%E4%BA%91%E5%8C%A3%E5%AD%90%E5%A0%A1%E5%9E%92%E6%9C%BAfastjson%E6%BC%8F%E6%B4%9E.md
海康威视运行管理中心fastjson漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E8%BF%90%E8%A1%8C%E7%AE%A1%E7%90%86%E4%B8%AD%E5%BF%83fastjson%E6%BC%8F%E6%B4%9E.md
Array VPN任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Array%20VPN/Array%20VPN%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
万户OA-upload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231126-新增漏洞
用友NC word.docx任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%20word.docx%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
用友NC的download文件存在任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%9A%84download%E6%96%87%E4%BB%B6%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
泛微e-cology9_SQL注入-CNVD-2023-12632https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology9_SQL%E6%B3%A8%E5%85%A5-CNVD-2023-12632.md
TOTOLINK A3700R命令执行漏洞CVE-2023-46574https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%B7%AF%E7%94%B1%E5%99%A8/TOTOLINK%20A3700R%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9ECVE-2023-46574.md
Splunk-Enterprise远程代码执行漏洞(CVE-2023-46214)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Splunk%20Enterprise/Splunk-Enterprise%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-46214).md
https://patch-diff.githubusercontent.com/pygopher/POC#20231124-新增漏洞
华为Auth-Http Serve任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%8D%8E%E4%B8%BAAuth-Http%20Serve/%E5%8D%8E%E4%B8%BAAuth-Http%20Serve%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
昂捷ERP WebService接口 SQL注入漏洞(QVD-2023-45071)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%98%82%E6%8D%B7ERP/%E6%98%82%E6%8D%B7ERP%20WebService%E6%8E%A5%E5%8F%A3%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(QVD-2023-45071).md
好视通视频会议系统 toDownload.do接口 任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A5%BD%E8%A7%86%E9%80%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AE%E7%B3%BB%E7%BB%9F/%E5%A5%BD%E8%A7%86%E9%80%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AE%E7%B3%BB%E7%BB%9F%20toDownload.do%E6%8E%A5%E5%8F%A3%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231123-新增漏洞
大华智能物联ICC综合管理平台readpic任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A7%E5%8D%8E/%E5%A4%A7%E5%8D%8E%E6%99%BA%E8%83%BD%E7%89%A9%E8%81%94ICC%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0readpic%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Apache-Submarine-SQL注入漏洞CVE-2023-37924https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache-Submarine-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9ECVE-2023-37924.md
H3C网络管理系统任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/H3C/H3C%E7%BD%91%E7%BB%9C%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
广州图创图书馆集群管理系统存在未授权访问https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E5%88%9B%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E5%B9%BF%E5%B7%9E%E5%9B%BE%E5%88%9B%E5%9B%BE%E4%B9%A6%E9%A6%86%E9%9B%86%E7%BE%A4%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE.md
I Doc View任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/iDocView/I%20Doc%20View%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
致远OA M3 Server 反序列化漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%20M3%20Server%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E.md
pyLoad远程代码执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/pyLoad/pyLoad%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231120-新增漏洞
金蝶OA-EAS系统 uploadLogo.action 任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6OA-EAS%E7%B3%BB%E7%BB%9F%20uploadLogo.action%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
浙大恩特客户资源管理系统 文件上传和sql注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F/%E6%B5%99%E5%A4%A7%E6%81%A9%E7%89%B9%E5%AE%A2%E6%88%B7%E8%B5%84%E6%BA%90%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E5%92%8Csql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
锐捷RG-UAC统一上网行为管理与审计系统管理员密码泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7RG-UAC%E7%BB%9F%E4%B8%80%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E4%B8%8E%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81%E6%B3%84%E9%9C%B2.md
Appium Desktop CVE-2023-2479漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Appium%20Desktop/Appium%20Desktop%20CVE-2023-2479%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231119-新增漏洞
用友U8-cloud RegisterServlet接口存在SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-cloud%20RegisterServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
SysAid远程命令执行漏洞(CVE-2023-47246)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/SysAid/SysAid%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2023-47246%EF%BC%89.md
CVE-2023-4357-Chrome-XXE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Chrome/CVE-2023-4357-Chrome-XXE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231117-新增漏洞
金蝶OA云星空 ScpSupRegHandler 任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6OA%E4%BA%91%E6%98%9F%E7%A9%BA%20ScpSupRegHandler%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231116-新增漏洞
迪普DPTech VPN 任意文件读取https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%BF%AA%E6%99%AE/%E8%BF%AA%E6%99%AEDPTech%20VPN%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md
蓝凌OAsysUiComponent 文件存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8COAsysUiComponent%20%E6%96%87%E4%BB%B6%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
通达OA get_datas.php前台sql注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA%20get_datas.php%E5%89%8D%E5%8F%B0sql%E6%B3%A8%E5%85%A5.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231109-新增漏洞
IP-guard WebServer 远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/IP%20guard%20WebServer/IP-guard%20WebServer%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231108-新增漏洞
奇安信360天擎getsimilarlistSQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/%E5%A5%87%E5%AE%89%E4%BF%A1360%E5%A4%A9%E6%93%8EgetsimilarlistSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
致远M1 usertokenservice 反序列化RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9CM1%20usertokenservice%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231107-新增漏洞
jshERP信息泄露漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/jshERP/jshERP%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
致远OA wpsAssistServlet任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9COA%20wpsAssistServlet%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
金和OA任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%92%8COA/%E9%87%91%E5%92%8COA%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231103-新增漏洞
XXL-JOB默认accessToken身份绕过漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/XXL-JOB/XXL-JOB%E9%BB%98%E8%AE%A4accessToken%E8%BA%AB%E4%BB%BD%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md
Confluence身份认证绕过(CVE-2023-22518)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Confluence/Confluence%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87(CVE-2023-22518).md
https://patch-diff.githubusercontent.com/pygopher/POC#20231031-新增漏洞
F5 BIG-IP 远程代码执行漏洞(CVE-2023-46747)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/F5-BIG-IP/F5%20BIG-IP%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2023-46747).md
Cisco IOS XE CVE-2023-20198权限提升漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Cisco/Cisco%20IOS%20XE%20CVE-2023-20198%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231030-新增漏洞
JAVA Public CMS 后台RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Public%20CMS/JAVA%20Public%20CMS%20%E5%90%8E%E5%8F%B0RCE%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231026-新增漏洞
Apache ActiveMQ远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20ActiveMQ%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231025-新增漏洞
用友U8-Cloud upload任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%20upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
安美数字酒店宽带运营系统SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%AE%89%E7%BE%8E%E6%95%B0%E5%AD%97%E9%85%92%E5%BA%97%E5%AE%BD%E5%B8%A6%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9F/%E5%AE%89%E7%BE%8E%E6%95%B0%E5%AD%97%E9%85%92%E5%BA%97%E5%AE%BD%E5%B8%A6%E8%BF%90%E8%90%A5%E7%B3%BB%E7%BB%9FSQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
泛微E-MobileServer远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-MobileServer%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
蓝凌OA treexml.tmpl 远程命令执行漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8COA%20treexml.tmpl%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231021-新增漏洞
海康威视综合安防管理平台信息泄露https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86/%E6%B5%B7%E5%BA%B7%E5%A8%81%E8%A7%86%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231020-新增漏洞
蓝凌EIS智慧协同平台saveImg接口存在任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%93%9D%E5%87%8COA/%E8%93%9D%E5%87%8CEIS%E6%99%BA%E6%85%A7%E5%8D%8F%E5%90%8C%E5%B9%B3%E5%8F%B0saveImg%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
用友NC-Cloud uploadChunk 任意文件上传漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC-Cloud%20uploadChunk%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
深信服下一代防火墙NGAF RCE漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E4%BF%A1%E6%9C%8D/%E6%B7%B1%E4%BF%A1%E6%9C%8D%E4%B8%8B%E4%B8%80%E4%BB%A3%E9%98%B2%E7%81%AB%E5%A2%99NGAF%20RCE%E6%BC%8F%E6%B4%9E.md
金蝶EAS myUploadFile任意文件上传https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E8%9D%B6/%E9%87%91%E8%9D%B6EAS%20myUploadFile%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
用友 GRP U8 license_check.jsp 存在SQL注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20GRP%20U8%20license_check.jsp%20%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md
https://patch-diff.githubusercontent.com/pygopher/POC#20231018-新增漏洞
360天擎 - 未授权与sql注入https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E5%A4%A9%E6%93%8E/360%E5%A4%A9%E6%93%8E%20-%20%E6%9C%AA%E6%8E%88%E6%9D%83%E4%B8%8Esql%E6%B3%A8%E5%85%A5.md
深信服SANGFOR终端检测响应平台 - 任意用户免密登录,前台RCEhttps://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E4%BF%A1%E6%9C%8D/%E6%B7%B1%E4%BF%A1%E6%9C%8DSANGFOR%E7%BB%88%E7%AB%AF%E6%A3%80%E6%B5%8B%E5%93%8D%E5%BA%94%E5%B9%B3%E5%8F%B0%20-%20%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%85%8D%E5%AF%86%E7%99%BB%E5%BD%95,%E5%89%8D%E5%8F%B0RCE.md
深信服下一代防火墙NGAF任意文件读取漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B7%B1%E4%BF%A1%E6%9C%8D/%E6%B7%B1%E4%BF%A1%E6%9C%8D%E4%B8%8B%E4%B8%80%E4%BB%A3%E9%98%B2%E7%81%AB%E5%A2%99NGAF%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
Confluence 未授权提权访问漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Confluence/Confluence%20%E6%9C%AA%E6%8E%88%E6%9D%83%E6%8F%90%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md
泛微e-office 未授权访问https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office%20%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE.md
金山终端安全系统V9.0 SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E9%87%91%E5%B1%B1/%E9%87%91%E5%B1%B1%E7%BB%88%E7%AB%AF%E5%AE%89%E5%85%A8%E7%B3%BB%E7%BB%9FV9.0%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#2023926-新增漏洞
JumpServer未授权访问漏洞 CVE-2023-42442https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JumpServer/JumpServer%E6%9C%AA%E6%8E%88%E6%9D%83%E6%BC%8F%E6%B4%9E.md
Craft CMS远程代码执行漏洞 CVE-2023-41892https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Craft/Craft%20CMS%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9ECVE-2023-41892.md
WinRAR CVE-2023-38831 漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/WinRAR/WinRAR%20CVE-2023-38831.md
用友 GRP-U8 bx_historyDataCheck.jsp SQL注入漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20GRP-U8%20bx_historyDataCheck.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
https://patch-diff.githubusercontent.com/pygopher/POC#2023922-新增漏洞
Joomla 未授权漏洞CVE-2023-23752https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Joomla/Joomla%20%E6%9C%AA%E6%8E%88%E6%9D%83%E6%BC%8F%E6%B4%9ECVE-2023-23752.md
https://patch-diff.githubusercontent.com/pygopher/POC#2023919-新增漏洞
smanga存在未授权远程代码执行漏洞 CVE-2023-36076https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/smanga/smanga%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md
JFinalCMS 任意文件读取漏洞(CVE-2023-41599)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/JFinalCMS/JFinalCMS%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2023-41599).md
https://patch-diff.githubusercontent.com/pygopher/POC#2023914-新增漏洞
致远OA前台用户重置密码漏洞https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/%E8%87%B4%E8%BF%9COA/%E8%87%B4%E8%BF%9C%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E4%BF%AE%E6%94%B9.md
Apache Spark命令执行漏洞(CVE-2023-32007)https://patch-diff.githubusercontent.com/pygopher/POC/blob/main/Apache/Apache%20Spark%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2023-32007%EF%BC%89.md
https://patch-diff.githubusercontent.com/pygopher/POC#免责声明
https://starchart.cc/wy876/POC
wiki.wy876.cnhttps://wiki.wy876.cn
Readme https://patch-diff.githubusercontent.com/pygopher/POC#readme-ov-file
Please reload this pagehttps://patch-diff.githubusercontent.com/pygopher/POC
Activityhttps://patch-diff.githubusercontent.com/pygopher/POC/activity
0 starshttps://patch-diff.githubusercontent.com/pygopher/POC/stargazers
0 watchinghttps://patch-diff.githubusercontent.com/pygopher/POC/watchers
0 forkshttps://patch-diff.githubusercontent.com/pygopher/POC/forks
Report repository https://patch-diff.githubusercontent.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2Fpygopher%2FPOC&report=pygopher+%28user%29
Releaseshttps://patch-diff.githubusercontent.com/pygopher/POC/releases
Packages 0https://patch-diff.githubusercontent.com/users/pygopher/packages?repo_name=POC
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.