admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.Referenceshttps://github.com/WhiteRabbitc/WhiteRabbitc.github.io/blob/master/cve/DKCMS_9.4_sql_injection.dochttps://blog.whiterabbitxyj.com/cve/DKCMS_9.4_sql_injection.doc