Skip to content

Latest commit

 

History

History
23 lines (16 loc) · 1.18 KB

sql.md

File metadata and controls

23 lines (16 loc) · 1.18 KB

SQL injection exists in the ibos office OA. Procedure

official website:http://www.ibos.com.cn/

version:4.5.5

Function point: Background Management = "Address Book Management =" Department and User Management = "Export user function

Route: r=dashboard/user/export&uid=X

The injection parameter: uid exists

The database name was successfully exploded using sqlmap WPS图片(2) Invoke the exportUser() method through the actionExport() method

WPS图片(3) The exportUser() method calls the fetchAllByUids() method of the model layer WPS图片(4) Finally, the SQL statement is executed in the wrapUserInfo() method WPS图片(5) WPS图片(6) WPS图片(7)