P2p financial security: Multiple SQL injection vulnerabilities on a platform

Source: Internet
Author: User

P2p financial security: Multiple SQL injection vulnerabilities on a platform

P2p financial security: Multiple SQL injection vulnerabilities on a platform

Qian loan Network (www.moneydai.com), as a professional P2P network lending institution, is affiliated to Shenzhen xingrong Internet Financial Service Co., Ltd., a subsidiary of Zhonghe group, with a registered capital of 10 million RMB, with the increasing development of the platform, the registered capital has increased to 2014 yuan in 50 million. The specific point of SQL injection is: http://www.moneydai.com: 80/wap/Touzi/turndetail/id/* sqlmap injection results




We recommend that you check all the back-end SQL statements of the entire site, especially the id parameter. Do not splice the SQL statement.

Solution:

1. Check all SQL statements at the backend. Do not splice them;
2. Change WAF ....
 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.