大汉版通JCMS两处越权+两处SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 合集吗 ### 详细说明: 第一个: /jcms/workflow/design/que_model.jsp 第二个: /jcms/short_message/que_recemsg.jsp 两处在一些版本里面都有越权+SQL注入。 http://www.panxian.gov.cn/jcms/workflow/design/que_model.jsp?userid= [<img src="https://images.seebug.org/upload/201406/09224016003fa99acaab2b9c74eb502fc0631761.png" alt="image009.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201406/09224016003fa99acaab2b9c74eb502fc0631761.png) http://www.changde.gov.cn/jcms/workflow/design/que_model.jsp?userid= [<img src="https://images.seebug.org/upload/201406/09224035784b244aaa1c4d50b5466d8e2c902162.png" alt="image011.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201406/09224035784b244aaa1c4d50b5466d8e2c902162.png) http://www.cshtz.gov.cn/jcms/workflow/design/que_model.jsp [<img src="https://images.seebug.org/upload/201406/092240579ffded2534b9f0978107d254bfaba8bb.png" alt="image013.png" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息