欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  网络运营

上海大智慧某平台存在SQL注入漏洞

程序员文章站 2024-01-23 09:47:16
    POST /MobileTrade/myReservationStep1.php HTTP/1.1 Content-Length: 63 C...

 

 

POST /MobileTrade/myReservationStep1.php HTTP/1.1
Content-Length: 63
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: https://dtsmt.gw.com.cn/
Cookie: PHPSESSID=kdf3fbjklgojpiqlngqiqnu0r1; TRADE_KEEP_SESSION=Y; TRADE_FILTER_ZERO=Y
Host: dtsmt.gw.com.cn
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*

policyid=1013&productid=581

 

上海大智慧某平台存在SQL注入漏洞

 

 

解决方案: