P2p financial security: Multiple SQL injection vulnerabilities on a platform
P2p financial security: Multiple SQL injection vulnerabilities on a platform
Qian loan Network (www.moneydai.com), as a professional P2P network lending institution, is affiliated to Shenzhen xingrong Internet Financial Service Co., Ltd., a subsidiary of Zhonghe group, with a registered capital of 10 million RMB, with the increasing development of the platform, the registered capital has increased to 2014 yuan in 50 million. The specific point of SQL injection is: http://www.moneydai.com: 80/wap/Touzi/turndetail/id/* sqlmap injection results
We recommend that you check all the back-end SQL statements of the entire site, especially the id parameter. Do not splice the SQL statement.
Solution:
1. Check all SQL statements at the backend. Do not splice them;
2. Change WAF ....