### 简要描述: RT ### 详细说明: 山东农友软件公司官网:http://www.nongyou.com.cn/ 案例如下: http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 http://221.2.171.59:8000/Swgk/Default.aspx?st=1&deptid=52 http://222.135.109.70:8100/Swgk/Default.aspx?st=1&deptid=52 http://61.133.119.187:8089/Swgk/Default.aspx?st=1&deptid=52 http://221.2.156.181:8100//Swgk/Default.aspx?st=1&deptid=52 http://221.2.149.47:8100/Swgk/Default.aspx?st=1&deptid=52 http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 参数 deptid存在注入 1.测试案例:http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png) 2.测试案例:http://221.2.149.47:8100/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/3015282918d42cdb605b335bacee9018e10da544.png" alt="2.png" width="600"...
### 简要描述: RT ### 详细说明: 山东农友软件公司官网:http://www.nongyou.com.cn/ 案例如下: http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 http://221.2.171.59:8000/Swgk/Default.aspx?st=1&deptid=52 http://222.135.109.70:8100/Swgk/Default.aspx?st=1&deptid=52 http://61.133.119.187:8089/Swgk/Default.aspx?st=1&deptid=52 http://221.2.156.181:8100//Swgk/Default.aspx?st=1&deptid=52 http://221.2.149.47:8100/Swgk/Default.aspx?st=1&deptid=52 http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 参数 deptid存在注入 1.测试案例:http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png) 2.测试案例:http://221.2.149.47:8100/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/3015282918d42cdb605b335bacee9018e10da544.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/3015282918d42cdb605b335bacee9018e10da544.png) 以上均可存在注入。 ### 漏洞证明: 1.测试案例:http://222.135.127.190:7000/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/30152638f04887c9d0ebf67b856065ce3713b588.png) 2.测试案例:http://221.2.149.47:8100/Swgk/Default.aspx?st=1&deptid=52 [<img src="https://images.seebug.org/upload/201501/3015282918d42cdb605b335bacee9018e10da544.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/3015282918d42cdb605b335bacee9018e10da544.png)