PowerPMS File.ashx存在SQL注入漏洞

2025-10-13 PowerPMS PoC No

Description

PowerPMS系统的GetCreateTableScript功能存在SQL注入漏洞,攻击者可通过构造恶意输入绕过身份验证,直接操纵数据库查询语句,可能导致用户敏感信息泄露(如用户名、密码哈希值)、未授权账户接管或数据库内容篡改,需紧急修补参数化查询或输入过滤机制。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities