taocms icon indicating copy to clipboard operation
taocms copied to clipboard

There is SQL blind injection at "Management Link"

Open bkfish opened this issue 3 years ago • 0 comments

analysis

The location of the vulnerability is line 33 in taocms\include\Model\Article.php, and the incoming sql statement in the update() method does not use intval to process id,and Link.php extends Article image

image

poc

edit link image image then edit id as 2)and+sleep(5)--+ image

bkfish avatar Jan 04 '22 02:01 bkfish