Apabi图书系统多个参数MSSQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 厂商: ``` http://gw.apabi.com/ 北京方正阿帕比技术有限公司 ``` SQL注入点: ``` /netlinkhandler.asp?lang=gb&DocGroupID=**&FieldID=**&FieldName=Creator&FieldType=1&QueryValue=****&Repeatable=True 其中:DocGroupID、FieldID这2个参数都是存在SQL注入的 ``` 互联网自动采集案例5枚: ``` http://202.117.24.8/dlib/netlinkhandler.asp?lang=gb&DocGroupID=2&FieldID=3&FieldName=Creator&FieldType=1&QueryValue=%C1%D6%C9%BD&Repeatable=True http://210.37.2.181/dlib/netlinkhandler.asp?lang=gb&DocGroupID=24&FieldID=516&FieldName=Creator&FieldType=1&QueryValue=%BA%A3%C4%CF%B0%AE%C0%D6%C5%AE%D7%D3%BA%CF%B3%AA%CD%C5&Repeatable=False http://202.195.177.13/ebook/netlinkhandler.asp?lang=gb&DocGroupID=2&FieldID=3&FieldName=Creator&FieldType=1&QueryValue=%BA%AB%CC%A9%C2%D7&Repeatable=True http://202.118.250.140/dlib/netlinkhandler.asp?lang=gb&DocGroupID=2&FieldID=3&FieldName=Creator&FieldType=1&QueryValue=%BB%C6%C1%F7%D0%CB%2C+%C5%A3%CA%A4%C0%FB&Repeatable=True...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息