某通用政务大厅系统SQL注射漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 某通用政务大厅系统SQL注射漏洞 ### 详细说明: google关键词 inurl:permissionitem_list_Sort.jspx?sortcode= 技术支持:深圳太极软件有限公司 存在注入漏洞,影响多个地方的政务大厅 如下,测试后均存在漏洞 存在漏洞的参数是sortcode参数 ``` http://www.kfxzzx.gov.cn/permissionitem_list_Sort.jspx?sortcode=003003&areaid=410203 http://222.143.52.13/permissionitem_list_Sort.jspx?sortcode=001001012&areaid=410100 http://www.gzegn.gov.cn/gzzfwz/permissionitem_list_Sort.jspx?sortcode=002018 http://smwsbsdt.xintai.gov.cn/permissionitem_list_Sort.jspx?sortcode=002001015 http://www.gazwzx.org:8888/permissionitem_list_Sort.jspx?sortcode=002006&areaid=520555 http://fw.hzzk.gov.cn/permissionitem_list_Sort.jspx?sortcode=001002004 http://www.zyszwdt.gov.cn/permissionitem_list_Sort.jspx?sortcode=002003002&areaid=620700 http://www.gzdpc.gov.cn:8080/gzzfwz/permissionitem_list_Sort.jspx?sortcode=002026 http://www.gzfg.gov.cn:8080/permissionitem_list_Sort.jspx?sortcode=002001017&areaid=520327 http://58.42.237.134:8888/permissionitem_list_Sort.jspx?sortcode=001015&areaid=520000...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息