Difference between revisions of "一卡通信息管理系統 SQL注入漏洞/zh-cn"
From PwnWiki
(Created page with "该漏洞已通过验证") |
(Created page with "==SQL注入==") |
||
| Line 9: | Line 9: | ||
|} | |} | ||
</center> | </center> | ||
| − | |||
==漏洞信息== | ==漏洞信息== | ||
| − | + | 此系统存在默认弱口令,以及前台sql注入。 | |
| − | |||
| − | |||
| − | |||
==FOFA== | ==FOFA== | ||
<pre> | <pre> | ||
| Line 20: | Line 16: | ||
</pre> | </pre> | ||
| − | |||
==弱口令== | ==弱口令== | ||
| − | |||
<pre> | <pre> | ||
super | super | ||
| Line 29: | Line 23: | ||
</pre> | </pre> | ||
| − | |||
==SQL注入== | ==SQL注入== | ||
| − | |||
| − | + | 用户名处存在SQL注入漏洞,使用BurpSuite插件利用(在用户名处加入<code>*</code>)。 | |
| − | |||
| − | |||
https://github.com/c0ny1/sqlmap4burp-plus-plus/ | https://github.com/c0ny1/sqlmap4burp-plus-plus/ | ||
Revision as of 09:58, 5 July 2021
| 该漏洞已通过验证
本页面的EXP/POC/Payload经测试可用,漏洞已经成功复现。 |
漏洞信息
此系统存在默认弱口令,以及前台sql注入。
FOFA
"Content/images/login/logo.png" && "/Content/js/core/knockout-2.2.1.js"
弱口令
super 1234