• 2024-05-19The cowherd and the weaving maid
    ThecowherdandtheweavingmaidInthecelestialcourtoftheJadeEmperorlivedsevenprincesses.Eachhadtheirchosenplaceincourt,buttheyoungestprincesshadaspecialskill.Shecouldpluckcloudsfromtheskyandspinthemintothesoftestrob
  • 2024-05-11The cowherd and the weaving maid
    ThecowherdandtheweavingmaidInthecelestialcourtoftheJadeEmperorlivedsevenprincesses.Eachhadtheirchosenplaceincourt,buttheyoungestprincesshadaspecialskill.Shecouldpluckcloudsfromtheskyandspinthemintothesoftestrob
  • 2024-01-17从OA中将加密文件解密并保存本地,或者保存到共享盘
     1、根据requestid 找出对应docid select *  from  formtable_main_291 where requestid=869869 2、 利用这个id继续查询select top 10  *  from  docimagefile where  docid = 46539找到对应的imagefileid  3、select t1.imagefilena
  • 2023-11-28E9代码使用事务
     注意代码里有两行update语句第一行是文本值,可以修改。第二行fpsl 是数字,改为文本的话会报错。提交事务,最终效果两行都没有改变。证明事务回滚成功。packagecom.test;importcom.engine.sunnypol.util.SapRfc;importorg.apache.http.client.config.RequestConfi
  • 2023-09-04泛微E-cology FileDownloadForOutDoc SQL注入漏洞(CVE-2023-15672)
    漏洞简介泛微e-cology未对用户的输入进行有效的过滤,直接将其拼接进了SQL查询语句中,导致系统出现SQL注入漏洞。远程未授权攻击者可利用此漏洞获取敏感信息,进一步利用可能获取目标系统权限等。影响版本Ecology9.x补丁版本<10.58.0;Ecology8.x补丁版本<10.58.0漏洞复现fo
  • 2023-07-17泛微ecology FileDownloadForOutDoc-前台sql注入
    厂商发布漏洞补丁Ecology_security_20230707_v9.0_v10.58.0.ziphttps://www.weaver.com.cn/cs/package/Ecology_security_20230707_v9.0_v10.58.0.zip?v=2023070700分析补丁文件ecology\WEB-INF\myclasses\weaver\security\rules\ruleImp\SecurityRuleForOutDocForSql.class