系统名称:学校综合管理平台
厂商:上海安脉计算机科技有限公司
关键字:版权所有:上海安脉计算机科技有限公司
系统架构:ASPX+MSSQL
漏洞文件:OA/repair/staticStat.aspx
注入参数:seldep
枚举部分案例:
http://anmai.net:81/OA/repair/staticStat.aspx
http://jwxx.am.jsedu.sh.cn/ANMAI/OA/repair/staticStat.aspx
http://bssyxxgl.eicbs.com/OA/repair/staticStat.aspx
http://cjzx.am.jsedu.sh.cn/OA/repair/staticStat.aspx
http://glpt.nhshs.edu.sh.cn/OA/repair/staticStat.aspx
http://218.78.241.80/anmai/OA/repair/staticStat.aspx
http://www.aqyz.net/anmai/OA/repair/staticStat.aspx
http://218.22.96.74:8899/anmai/OA/repair/staticStat.aspx
http://120.69.153.68:8002/anmai654202_458357247/OA/repair/staticStat.aspx
http://222.82.229.202:2010/anmai/OA/repair/staticStat.aspx
http://58.118.20.5/anmai/OA/repair/staticStat.aspx
http://124.228.32.115:81/OA/repair/staticStat.aspx
http://luoxzx.am.jsedu.sh.cn/OA/repair/staticStat.aspx
http://www.syzxyz.com:8008/OA/repair/staticStat.aspx
等等。。
漏洞验证:
这里以http://anmai.net:81/OA/repair/staticStat.aspx为例:

数据包如下:
相关代码如下:


当前数据库:

http://anmai.net:81/OA/repair/staticStat.aspx为例:

数据包如下:
相关代码如下:


当前数据库:
