Product
RainyGao DocSys versions up to 2.02.85 contain a remote SQL injection vulnerability in the Database Management component, allowing unauthenticated attackers to execute arbitrary SQL commands via the url argument.