中企动力门户CMS membersarticCategoryId SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

通用Sql 注入点: http://www.xxx.com/membersarticle_list/&membersarticleScope=1&isShowPublishDate=&membersarticleCategoryId=1*&membersarticleEndDate=YYYY-MM-DD&button=%25E6%2590%259C%25E7%25B4%25A2&initKeyWords=1&membersarticleKeyWord=&keyWord=%25E8%25AF%25B7%25E6%2582%25A8%25E6%258F%2590%25E4%25BE%259B%25E6%2590%259C%25E7%25B4%25A2%25E5%2585%25B3%25E9%2594%25AE%25E8%25AF%258D&needKeyWord=&membersarticleStartDate=YYYY-MM-DD.html 注入参数:membersarticleCategoryId 根据中企动力官网介绍,影响大约几十万的用户,有不少的大企业用户,影响很是广泛。 ![](https://images.seebug.org/contribute/32a4c1bd-bb17-4964-9fc8-d76286d80fc8-QQ截图20151231174931.png)

0%
暂无可用Exp或PoC
当前有0条受影响产品信息