
Prueba de concepto de exploit para CVE-2024-48307, una vulnerabilidad de inyección SQL en la API getDictItemsByTable de Jeecg-Boot. Admite escaneo de URL individual y por lotes con salida de detalles opcional.
Parámetros:
options:
-h, --help show this help message and exit
-u URL, --url URL Introduzca la URL a detectar
-f FILE, --file FILE Introduzca la dirección del archivo con una URL por línea
-c CONTENT, --content CONTENT
Introduzca un valor cualquiera para ver los detalles de la vulnerabilidad
Ejemplos:
Detección individual:
python .\CVE-2024-48307Poc.py -u URL
Detección por lotes:
python .\CVE-2024-48307Poc.py -f urls.txt
Ver fuga de información:
python .\CVE-2024-48307Poc.py -u URL -c 1 (valor cualquiera)
FOFA:
title=="JeecgBoot 企业级低代码平台" || body="window._CONFIG['imgDomainURL'] = 'http://localhost:8080/jeecg-boot/" || title="Jeecg-Boot 企业级快速开发平台" || title="Jeecg 快速开发平台" || body="'http://fileview.jeecg.com/onlinePreview'" || title=="JeecgBoot 企业级低代码平台" || title=="Jeecg-Boot 企业级快速开发平台" || title=="JeecgBoot 企业级快速开发平台" || title=="JeecgBoot 企业级快速开发平台" || title="Jeecg 快速开发平台" || title="Jeecg-Boot 快速开发平台" || body="积木报表" || body="jmreport"