某期刊投稿系统SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: 南京杰诺瀚期刊投稿系统存在SQL延迟注入漏洞,可获取数据库任意数据... 官网:http://www.025journal.com/ 案例: http://www.cjge-manuscriptcentral.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.lcmzxzz.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://gaojian.xhnj.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://xb.cuit.edu.cn/tougao/GetInfo.aspx?type=getwkqi&value=1 http://j.chinatransducers.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.chinaelectrondevices.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.linpi.net/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.jsnyxb.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.lcsjwk.com/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.mfskin.net/tougao/GetInfo.aspx?type=getwkqi&value=1 http://www.gjmzyfs.com/tougao/GetInfo.aspx?type=getwkqi&value=1 是延时注入 ### 漏洞证明: 我就只演示1个站了 http://www.cjge-manuscriptcentral.com/tougao/GetInfo.aspx?type=getwkqi&value=1 sqlmap.py -u...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息