该漏洞报告总共包含一处无限制getshell漏洞+三处SQL注入漏洞 两处重复
0x01 无限制getshell漏洞
/Server/CmxRemoteDesktop.php?pgid=App_Show&ID=1
ID参数提交单引号,即可爆出网站绝对路径,然后即可利用into outfile无限制getshell

http://58.217.117.20:81/Server/my.php

0x02 sql注入1
/Server/CmxPagedQuery.php?pgid=AppList

0x03 sql注入2
/Server/CmxRemoteDesktop.php?pgid=AppList

0x04 sql注入3
/Server/CmxFolder.php?pgid=AddApp_selectUserGroup

案例很多,随便给5个:
http://218.27.137.242:8080/
http://222.177.213.190:8888/
http://117.132.15.88:8001/
http://221.224.116.210:81/
http://221.238.243.237:8000/