
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
Parameters:
options:
-h, --help show this help message and exit
-u URL, --url URL Please enter the URL to be detected
-f FILE, --file FILE Please enter the file path containing one URL per line
-c CONTENT, --content CONTENT
Enter any value to view vulnerability details
Examples:
Single detection:
python .\CVE-2024-48307Poc.py -u URL
Batch detection:
python .\CVE-2024-48307Poc.py -f urls.txt
View leakage:
python .\CVE-2024-48307Poc.py -u URL -c 1 (any value)
FOFA:
title=="JeecgBoot Enterprise Low-Code Platform" || body="window._CONFIG['imgDomainURL'] = 'http://localhost:8080/jeecg-boot/" || title=="Jeecg-Boot Enterprise Rapid Development Platform" || title=="Jeecg Rapid Development Platform" || body="'http://fileview.jeecg.com/onlinePreview'" || title=="JeecgBoot Enterprise Low-Code Platform" || title=="Jeecg-Boot Enterprise Rapid Development Platform" || title=="JeecgBoot Enterprise Rapid Development Platform" || title=="JeecgBoot Enterprise Rapid Development Platform" || title=="Jeecg Rapid Development Platform" || title=="Jeecg-Boot Rapid Development Platform" || body="Jimu Report" || body="jmreport"