Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-22208 PoC — 迅易科技 74cms SQL注入漏洞

Source
Associated Vulnerability
Title:迅易科技 74cms SQL注入漏洞 (CVE-2020-22208)
Description:迅易科技 74cms是中国迅易科技公司的一套基于PHP和MySQL的在线招聘系统。 74cms 中存在SQL注入漏洞,该漏洞源于系统未对 plus/ajax_street.php 文件中的 X 参数做安全处理。攻击者可通过该漏洞执行非法SQL语句。以下产品及版本受到影响:74cms 3.2.0。
Description
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
File Snapshot

id: CVE-2020-22208 info: name: 74cms - ajax_street.php 'x' SQL Injection author: ritikchaddha ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.