当热浪袭向数据库:在 Z-Push 中发现 SQL 注入
xbow.com | 漏洞 | #vulnerability-research | #sql-injection | #web-security | #authentication | #z-push | #activesync
摘要
复盘 XBOW 在真实 Z-Push ActiveSync 服务器上发现 SQL 注入的经过:URL、请求头与 XML 载荷等常规尝试均告失败后,探查转向 Basic Authentication 认证机制,并在此挖出漏洞。
- 发布时间
- 收录时间
Skip to content