add Clinical Browsing System Boolean SQLi

This commit is contained in:
corp0ra1 2021-08-02 15:11:48 +08:00 committed by GitHub
parent 8229a84e96
commit 04fd2b8045
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 10 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

View File

@ -0,0 +1,10 @@
# Clinical Browsing System login.php Boolean SQLi
There is a Boolean SQL injection vulnerability in the login of clinical browsing system. Through this vulnerability, an attacker can directly log in to the system using the universal password such like \"1'or 1='1\", and even obtain sensitive information in the database through Boolean blind injection.
**FOFA query rule**: [body="/KView/ChromeBrowser.exe"](https://fofa.so/result?qbase64=Ym9keT0iL0tWaWV3L0Nocm9tZUJyb3dzZXIuZXhlIg%3D%3D)
# Demo
![](Clinical_Browsing_System_Boolean_SQLi.gif)