Description 郑州市金水区恒友摄影软件经营部恒友摄影软件存在SQL注入漏洞,恒友摄影软件≤V2.1.0版本中,查找主体支付记录过程中存在未校验传入参数,直接带入数据库查询,造成SQL注入漏洞。
References https://cn.t00ls.com/articles-74512.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%81%92%E5%8F%8B%E6%91%84%E5%BD%B1ERP/%E6%81%92%E5%8F%8B%E6%91%84%E5%BD%B1ERP%E7%9A%84login.ashx%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md https://www.cert.org.cn/publish/main/upload/File/CNVD202448.pdf
Related Vulnerabilities郑州市金水区恒友摄影软件经营部恒友摄影软件AddCustomer.ashx TypeID参数存在SQL注入漏洞郑州市金水区恒友摄影软件经营部恒友摄影软件findedCustomer.ashx 存在SQL注入漏洞郑州市金水区恒友摄影软件经营部恒友摄影软件myTask.ashx EmployeeName参数存在SQL注入漏洞郑州市金水区恒友摄影软件经营部恒友摄影软件存在SQL注入