### 简要描述:
### 详细说明:
某高校大型仪器设备开放共享管理平台通用SQL注入之二。
案例:
http://**.**.**.**/ShowFiles/EquWxList.aspx
http://**.**.**.**/syjx/share/ShowFiles/EquWxList.aspx
http://**.**.**.**/nxdyq/ShowFiles/EquWxList.aspx
http://**.**.**.**/ShowFiles/EquWxList.aspx
**.**.**.**/shiyan/share/ShowFiles/EquWxList.aspx
### 漏洞证明:
注入证明:
http://**.**.**.**/ShowFiles/EquWxList.aspx
[<img src="https://images.seebug.org/upload/201506/2413184018e7df71ba0da45845cac8c86890430b.png" alt="QQ图片20150624131522.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/2413184018e7df71ba0da45845cac8c86890430b.png)
存在注入:
[<img src="https://images.seebug.org/upload/201506/241319126dea9cfdbf1127c3d72193dc5b268d42.png" alt="QQ图片20150624131535.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/241319126dea9cfdbf1127c3d72193dc5b268d42.png)
爆出数据库表:
[<img src="https://images.seebug.org/upload/201506/241319222ab205bdc8b88cf34b3e19ed5987db0f.png" alt="QQ图片20150624131613.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201506/241319222ab205bdc8b88cf34b3e19ed5987db0f.png)
暂无评论