涉及中国科技教育网 与某些外贸网站
关键字: inurl:contentmanager.do?method=view
漏洞页面:/cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
title参数未过滤带入查询造成注入
http://60.247.10.155:8001/cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
www.cnstedu.cn/cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
http://kxsz.gdec.net/cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
http://www.cimuset.org//cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
http://www.fdstmc.org.cn//cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
http://www.chinaworldmall.cn//cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
http://www.sqkpym.org.cn/cms/columnmanager.do?method=NewsCommonSearch&title=1&type=new
结果:
60.247.10.155:8001
www.cnstedu.cn
kxsz.gdec.net
www.cimuset.org