
jeecg-boot-Schnittstelle getDictItemsByTable weist eine SQL-Injection-Schwachstelle auf.
Parameter:
options:
-h, --help show this help message and exit
-u URL, --url URL Bitte geben Sie die zu prüfende URL ein
-f FILE, --file FILE Bitte geben Sie den Dateipfad mit einer URL pro Zeile ein
-c CONTENT, --content CONTENT
Geben Sie einen beliebigen Wert ein, um die Details der Schwachstelle anzuzeigen
Beispiele:
Einzelprüfung:
python .\CVE-2024-48307Poc.py -u URL
Batchprüfung:
python .\CVE-2024-48307Poc.py -f urls.txt
Informationen anzeigen:
python .\CVE-2024-48307Poc.py -u URL -c 1 (beliebiger Wert)
FOFA:
title=="JeecgBoot Enterprise Low-Code Platform" || body="window._CONFIG['imgDomainURL'] = 'http://localhost:8080/jeecg-boot/" || title=="Jeecg-Boot Enterprise Rapid Development Platform" || title=="Jeecg Rapid Development Platform" || body="'http://fileview.jeecg.com/onlinePreview'" || title=="JeecgBoot Enterprise Low-Code Platform" || title=="Jeecg-Boot Enterprise Rapid Development Platform" || title=="JeecgBoot Enterprise Rapid Development Platform" || title=="JeecgBoot Enterprise Rapid Development Platform" || title=="Jeecg Rapid Development Platform" || title=="Jeecg-Boot Rapid Development Platform" || body="Block Report" || body="jmreport"