Skip to content

Latest commit

 

History

History
26 lines (14 loc) · 956 Bytes

sql.md

File metadata and controls

26 lines (14 loc) · 956 Bytes

SQL injection exists in ibos Office OA v4.5.5

official website:http://www.ibos.com.cn/

version:v4.5.5

Function point: Integrated office = "Recruitment management =" Contact record = "Export

WPS图片(1) POC

Route: r=recruit/contact/export&contactids=x

The injection parameter contactids exists

Successfully burst the database name by reporting an error injection

WPS图片(2)

Find the actionExport() method, which accepts only one parameter, contactids, and then fetchAll() under model to execute the SQL statement.

WPS图片(3)

Fetchall() is still some data processing operation.

WPS图片(4)