某图书馆书目检索系统存在通用型SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 某图书馆书目检索系统存在通用型SQL注入 ### 详细说明: 汇文图书馆数目检索系统存在SQL注入 注入点doctype 谷歌搜索关键字:inurl:/opac/search.php,影响范围很大 [<img src="https://images.seebug.org/upload/201412/04130614f0ca483bc418c82b861d5a6866b5b79a.png" alt="QQ截图20141204130534.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/04130614f0ca483bc418c82b861d5a6866b5b79a.png) 1、访问http://120.195.143.181:9090/opac/search.php 发现搜索有多处参数,于是提交时抓包 GET http://120.195.143.181:9090/opac/openlink.php?strText=sssssssssssssss&doctype=ALL&strSearchType=title&match_flag=forward&displaypg=20&sort=CATA_DATE&orderby=desc&showmode=list&location=ALL HTTP/1.1 Host: 120.195.143.181:9090 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://120.195.143.181:9090/opac/search.php Cookie:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息