### 简要描述:
RT
### 详细说明:
山东农友软件公司官网:http://www.nongyou.com.cn/
和这个漏洞 [WooYun: 某政府系统一处SQL注入](http://www.wooyun.org/bugs/wooyun-2015-097576) 是同一文件的但是不是同一目录下的注入,不知道算不算重复啊
案例如下:
http://61.133.119.187:8091/symItemView/ItemFifth.aspx?id=1
http://222.135.76.147:8200/symItemView/ItemFifth.aspx?id=1
http://222.135.127.190:7200/symItemView/ItemFifth.aspx?id=1
http://221.2.149.47:8200/symItemView/ItemFifth.aspx?id=1
http://218.59.205.41:8053/symItemView/ItemFifth.aspx?id=1
http://jwh.tanljgzx.gov.cn/symItemView/ItemFifth.aspx?id=1
http://221.2.171.59:8200/symItemView/ItemFifth.aspx?id=1
http://218.56.159.98:8001/symItemView/ItemFifth.aspx?id=1
http://123.134.189.60:8016/symItemView/ItemFifth.aspx?id=1
### 漏洞证明:
http://61.133.119.187:8091/symItemView/ItemFifth.aspx?id=1
[<img src="https://images.seebug.org/upload/201503/2219050814db0efe3207cbdd65808d58f2a0f996.png" alt="QQ图片20150322190517.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/2219050814db0efe3207cbdd65808d58f2a0f996.png)
http://221.2.149.47:8200/symItemView/ItemFifth.aspx?id=1
[<img src="https://images.seebug.org/upload/201503/221909014f53308c873932055264a4f0a7f1afd7.png" alt="QQ图片20150322190904.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/221909014f53308c873932055264a4f0a7f1afd7.png)
暂无评论