用友软件协作办公平台通用DBA权限SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: sys\sortListUI.jsp ``` String done=request.getParameter("done"); String nodeId=request.getParameter("nodeId"); String strWhere=""; String id=request.getParameter("id"); String srcName = BaseFunc.ISOToGBK(request.getParameter("srcName"));//注入点 String searchKey = StringUtil.NullToEmpty(BaseFunc.ISOToGBK(request.getParameter("searchKeyvalue")));//注入点 srcName = "".equals(srcName)|| "null".equals(srcName) || srcName==null?"":srcName; String lx=request.getParameter("lx");//0为分类项;1提示项 lx = "".equals(lx)|| "null".equals(lx) || lx==null?"0":lx; id = "".equals(id)|| "null".equals(id) || lx==null?"0":id; Sort sort= (Sort)ResourceManage.getContext("sort"); FieldSet fs=new WebFieldSet(); if("delete".equals(done)){ id=StringUtil.NullToEmpty(id).equals("")?"0":id; int row=sort.deleteSort(Integer.parseInt(id)); } DataTable DT; if(!searchKey.equals("")){ strWhere = "(SI03 like'"+srcName+"%' and SI10='"+lx+"') or SI01 like'%"+searchKey+"%' or SI02 like'%"+searchKey+"%'";//拼接...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息