Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-13086 PoC — CSZ CMS SQL注入漏洞

Source
Associated Vulnerability
Title: CSZ CMS SQL注入漏洞 (CVE-2019-13086)
Description:core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Description
CVE-2019-13086漏洞的复现以及poc实验代码
Readme
# CVE_POC_test
CVE-2019-13086漏洞的复现以及poc实验代码

原CVE信息:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13086

实验环境:
CSZ CMS架构+php5.4+MySQL 5.5+Apache 2.4

漏洞类型:
SQL注入漏洞  文件上传漏洞

简要说明:
在\cszcms\cszcms\core\MY_Security.php的csrf_show_error函数中 
HTTP包的User-Agent字段在被添加到数据库查询语句中之前没有任何内容检测
这成为了可被构造sql注入的地方

防御措施:当然是赶紧修改源码添加对http包的UA字段的检测了!
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →