Difference between revisions of "一卡通信息管理系統 SQL注入漏洞/zh-cn"
From PwnWiki
(Created page with "==SQL注入==") |
(Created page with "==弱口令==") |
||
| Line 30: | Line 30: | ||
| − | + | ==参考== | |
| − | = | ||
| − | |||
https://mp.weixin.qq.com/s/zxxOWSYgzY-z8GbBxEP_TQ | https://mp.weixin.qq.com/s/zxxOWSYgzY-z8GbBxEP_TQ | ||
Latest revision as of 09:58, 5 July 2021
| 该漏洞已通过验证
本页面的EXP/POC/Payload经测试可用,漏洞已经成功复现。 |
漏洞信息
此系统存在默认弱口令,以及前台sql注入。
FOFA
"Content/images/login/logo.png" && "/Content/js/core/knockout-2.2.1.js"
弱口令
super 1234