骑士CMS某接口1处SQL盲注#1(官网demo测试)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 骑士CMS某接口1处SQL盲注(官网demo测试) ### 详细说明: 手机客户端接口存在SQL注入,SELECT注入无关键字过滤,理论上可以获取任意数据。 : ``` http://demo.74cms.com/android/resume.php ``` 代码: ``` 15 if (!empty($aset['displayorder'])) 16 { 17 $arr=explode('>',$aset['displayorder']); 18 $arr[1]=preg_match('/asc|desc/',$arr[1])?$arr[1]:"desc"; 19 if ($arr[0]=="rtime") 20 { 21 $orderbysql=" ORDER BY r.refreshtime {$arr[1]}"; 22 } 23 } ``` displayorder参数过滤不正确导致SQL注入。 "displayorder":"rtime> abd #desc"时返回数据库错误: [<img src="https://images.seebug.org/upload/201504/2320221378bd0087001415e0775775488567aa3b.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/2320221378bd0087001415e0775775488567aa3b.png) "displayorder":"rtime> limit 1 #desc"返回一行数据: [<img src="https://images.seebug.org/upload/201504/232022276e23530696cf40d8ea262ddc13648ce2.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/232022276e23530696cf40d8ea262ddc13648ce2.png)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息