通达OA在retrieve_pwd.php参数SQL注入

2021-01-19 通达OA PoC No

Description

较早期的通达OA在retrieve_pwd.php文件的username参数过滤不严,导致存在SQL注入漏洞。攻击者可以通过BOOL注入的方法较快捷的获取内部数据库存储的敏感数据信息,包括用户数据。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities