• 2024-11-28schoolcms代码审计
    sql注入注入点:burp的数据包:POST/index.php?m=Admin&c=Article&a=DeleteHTTP/1.1Host:schoolcmsUpgrade-Insecure-Requests:1User-Agent:Mozilla/5.0(WindowsNT10.0;Win64;x64)AppleWebKit/537.36(KHTML,likeGecko)Chrome/125.0.6422.112Safari/537.36