SQL Chat 包含四个未经身份验证的 API 端点,这些端点接受客户端提供的数据库连接参数,并针对攻击者指定的主机执行任意 SQL 查询。攻击者可以连接到内部数据库、执行 SQL 命令、枚举数据库模式(schemas),并无需身份验证即可通过服务器网络进行横向移动(pivot)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet