Add CRMEB DaTong sid sqli

This commit is contained in:
xiaoheihei1107 2021-09-16 18:00:33 +08:00 committed by GitHub
parent 8a8a52f406
commit ca0126af9b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,9 @@
# CRMEB DaTong sid sqli
CRMEB open version v4 is a free and open source mall system, UINAPP+thinkphp6 framework mall. The sid parameter under the path of CRMEB open version /api/products has unfiltered SQL statement splicing, resulting in SQL injection.
FOFA **query rule**: [body="CRMEB" && body="/h5/js/app"](https://fofa.so/result?qbase64=Ym9keT0iQ1JNRUIiICYmIGJvZHk9Ii9oNS9qcy9hcHAi)
# Demo
![CRMEB_DaTong_sid_sqli](CRMEB_DaTong_sid_sqli.gif)