Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sql注入误报有些严重 #505

Open
Maysec opened this issue Feb 6, 2022 · 4 comments
Open

sql注入误报有些严重 #505

Maysec opened this issue Feb 6, 2022 · 4 comments

Comments

@Maysec
Copy link

Maysec commented Feb 6, 2022

rad联合w13scan扫描sql注入误报严重 经常出现js文件的时间型注入 并且无payload

@boy-hack
Copy link
Member

boy-hack commented Feb 9, 2022

可以提供下报告文件吗

@Maysec
Copy link
Author

Maysec commented Feb 11, 2022

扫描结果就是自己指定格式html或json文件 没有漏洞细节报告可以下载了

@boy-hack
Copy link
Member

提供下html报告就行

@Maysec
Copy link
Author

Maysec commented Feb 11, 2022

一开始以为是在js中发现接口进而sql注入 但工具好像是直接在js文件后拼接注入语句 目前扫到的所有sql注入漏洞都是如图的样子
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants