### 简要描述:
rt
### 详细说明:
rt
### 漏洞证明:
谷歌搜索:论文授权提交系统
第一处:
http://202.120.121.200/tasi/admin/convert/convert.asp?action=querylist
http://202.195.243.37/tasi/admin/convert/convert.asp?action=querylist
http://202.116.50.25/tasi/admin/convert/convert.asp?action=querylist
http://pss.uestc.edu.cn/tasi/admin/convert/convert.asp?action=querylist
http://202.120.146.49/tasi/admin/convert/convert.asp?action=querylist
http://202.203.222.222/tasi/admin/convert/convert.asp?action=querylist
http://paper.sysu.edu.cn/TASi/admin/convert/convert.asp?action=querylist
http://202.120.227.60/tasi/admin/convert/convert.asp?action=querylist
http://59.72.151.17:8000/admin/convert/convert.asp?action=querylist
http://202.197.127.125/tasi/admin/convert/convert.asp?action=querylist
POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1&convert=-1
第二处:
http://202.120.121.200/tasi/admin/authorize/authorize.asp?action=querylist
http://202.195.243.37/tasi/admin/authorize/authorize.asp?action=querylist
http://202.116.50.25/tasi/admin/authorize/authorize.asp?action=querylist
http://pss.uestc.edu.cn/tasi/admin/authorize/authorize.asp?action=querylist
http://202.120.146.49/tasi/admin/authorize/authorize.asp?action=querylist
http://202.203.222.222/tasi/admin/authorize/authorize.asp?action=querylist
http://paper.sysu.edu.cn/TASi/admin/authorize/authorize.asp?action=querylist
http://202.120.227.60/tasi/admin/authorize/authorize.asp?action=querylist
http://59.72.151.17:8000/admin/authorize/authorize.asp?action=querylist
http://202.197.127.125/tasi/admin/authorize/authorize.asp?action=querylist
POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&authorize=-1
第三处:
http://202.120.121.200/tasi/admin/catalog/catalog.asp?action=querylist
http://202.195.243.37/tasi/admin/catalog/catalog.asp?action=querylist
http://202.116.50.25/tasi/admin/catalog/catalog.asp?action=querylist
http://pss.uestc.edu.cn/tasi/admin/catalog/catalog.asp?action=querylist
http://202.120.146.49/tasi/admin/catalog/catalog.asp?action=querylist
http://202.203.222.222/tasi/admin/catalog/catalog.asp?action=querylist
http://paper.sysu.edu.cn/TASi/admin/catalog/catalog.asp?action=querylist
http://202.120.227.60/tasi/admin/catalog/catalog.asp?action=querylist
http://59.72.151.17:8000/admin/catalog/catalog.asp?action=querylist
http://202.197.127.125/tasi/admin/catalog/catalog.asp?action=querylist
txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1
测试第一处:http://202.120.121.200/tasi/admin/convert/convert.asp?action=querylist
POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&catalog=-1&convert=-1
[<img src="https://images.seebug.org/upload/201507/20172139dd732afee97444577f02fbb68fcd36bb.png" alt="QQ图片20150720172127.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/20172139dd732afee97444577f02fbb68fcd36bb.png)
测试第二处:http://202.195.243.37/tasi/admin/authorize/authorize.asp?action=querylist
POST参数:txtStuName=11&txtStuNo=11&cboCollege=&cboDegreeType=0&cboSubjectClass=&cboSubject=undefined&txtMajor=&public=&inputStartDate=&inputEndDate=&authorize=-1
[<img src="https://images.seebug.org/upload/201507/201722212964e6f4d4d5a2deb38d88067643dbe0.png" alt="QQ图片20150720172212.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/201722212964e6f4d4d5a2deb38d88067643dbe0.png)
以上均可复现
暂无评论