手机
当前位置:查字典教程网 >电脑 >电脑安全教程 >File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities
File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities
摘要:|FileStorePRO3.2BlindSQLInjection||___________________________________...

| File Store PRO 3.2 Blind SQL Injection |

|________________________________________|

Download from: /cgi/demo/fs/filestore.zip

- Need admin rights:

/confirm.php:

复制代码代码如下:

if(isset($_GET["folder"]) && $_GET["folder"]!="") {

$folder=$_GET["folder"];

} else {

exit("Bad Request");

}

if(isset($_GET["id"]) && $_GET["id"]!="") {

$id=$_GET["id"];

} else {

exit("Bad Request");

}

// Validate all inputs

// Added by SepedaTua on June 01, 2006 - /

/********************** SepedaTua ****************************/

/* Fields:

$folder

$id

*/

$search = array ('@@si',

'@@si',

'@([rn])[s] @',

'@&(quot|#34);@i',

'@&(amp|#38);@i',

'@&(lt|#60);@i',

'@&(gt|#62);@i',

'@&(nbsp|#160);@i',

'@&(iexcl|#161);@i',

'@&(cent|#162);@i',

'@&(pound|#163);@i',

'@&(copy|#169);@i',

'@&#(d );@e');

$replace = array ('',

'',

'1',

'"',

'&',

'',

' ',

chr(161),

chr(162),

chr(163),

chr(169),

'chr

(1)');

$ffolder = $folder;

$fid = $id;

$folder = preg_replace($search, $replace, $folder);

$id = preg_replace($search, $replace, $id);

-----

$SQL="SELECT `".DB_PREFIX."users`.*, `".DB_PREFIX."file_list`.`filename`, `".DB_PREFIX."file_list`.`descript` ";

$SQL.=" FROM `".DB_PREFIX."file_list` LEFT JOIN `".DB_PREFIX."users` ON `".DB_PREFIX."file_list`.`user_id`=`".DB_PREFIX."users`.`id`";

$SQL.=" WHERE `".DB_PREFIX."file_list`.`id`='".$id."'";

if(!$mysql->query($SQL))

{

exit($mysql->error);

}

if($mysql->num

【File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities】相关文章:

AlstraSoft Article Manager Pro 1.6 Blind SQL Injection Exploit

做好Web服务器的日常维护必备常识

Wysi Wiki Wyg 1.0 (index.php c) Local File Inclusion Vulnerability

金山毒霸教程之怎么快速卸载软件

如何防御与删除calc.exe病毒

MojoPersonals (mojoClassified.cgi mojo) Blind SQL Injection Exploit

mssql2005 DB权限导出一句话

avast无法卸载怎么办?

Arctic Issue Tracker 2.0.0 (index.php filter) SQL Injection Exploit

教你如何抢掉局域网内所有IP

精品推荐
分类导航