36 lines
2.3 KiB
MySQL
36 lines
2.3 KiB
MySQL
|
|
#劫持相关字典表 insert语句中的156即dictionary_id应替换为select筛选后中id字段的值
|
||
|
|
INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`)
|
||
|
|
VALUES ('劫持文件内容格式', 'CONTENT_TYPE_HIJACK', 'hijack content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1);
|
||
|
|
|
||
|
|
SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_HIJACK';
|
||
|
|
|
||
|
|
INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id)
|
||
|
|
VALUES('image/gif','image/gif',0,1,1,156),
|
||
|
|
('image/jpeg','image/jpeg',0,1,1,156),
|
||
|
|
('image/png','image/png',0,1,1,156),
|
||
|
|
('image/svg+xml','image/svg+xml',0,1,1,156),
|
||
|
|
('application/x-msdos-program','application/x-msdos-program',0,1,1,156),
|
||
|
|
('application/x-msdownload','application/x-msdownload',0,1,1,156),
|
||
|
|
('application/octet-stream','application/octet-stream',0,1,1,156),
|
||
|
|
('application/vnd.android.package-archive','application/vnd.android.package-archive',0,1,1,156),
|
||
|
|
('text/html','text/html',0,1,1,156);
|
||
|
|
|
||
|
|
#文件策略相关字典表 insert语句中的157即dictionary_id应替换为select筛选后中id字段的值
|
||
|
|
INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`)
|
||
|
|
VALUES('文件策略内容格式', 'CONTENT_TYPE_FILESTRATEGY', 'fileStrategy content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1);
|
||
|
|
|
||
|
|
SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_FILESTRATEGY';
|
||
|
|
|
||
|
|
INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id)
|
||
|
|
VALUES('template','template',0,1,1,157),
|
||
|
|
('html','html',0,1,1,157);
|
||
|
|
|
||
|
|
#注入脚本相关字典表 insert语句中的158即dictionary_id应替换为select筛选后中id字段的值
|
||
|
|
INSERT INTO `sys_data_dictionary_name`(`module_name`, `mark`, `remark`, `revision`, `create_time`, `modify_time`, `status`)
|
||
|
|
VALUES('注入脚本文件内容格式', 'CONTENT_TYPE_INSERTSCRIPT', 'insertScript content-type', '', '2019-05-21 00:00:00', '2019-05-21 00:00:00', 1);
|
||
|
|
|
||
|
|
SELECT * FROM sys_data_dictionary_name WHERE mark='CONTENT_TYPE_INSERTSCRIPT';
|
||
|
|
|
||
|
|
INSERT into sys_data_dictionary_item(item_code,item_value,item_sort,`status`,type,dictionary_id)
|
||
|
|
VALUES('css','css',0,1,1,158),
|
||
|
|
('js','js',0,1,1,158);
|