发新话题
打印

[转载]ITA Forum SQL Injection注入漏洞

[转载]ITA Forum SQL Injection注入漏洞

信息来源:www.securiteam.com

Summary
ITA Forum is "an online messaging system, all developed in PHP, using MySQL as the backend database".

Due to a vulnerability in the way ITA Forum handles incoming data a remote attacker can insert malicious SQL statements into existing ones. The following exploit code can be used to test your system for the mentioned vulnerability.

Credit:
The information has been provided by 1dt.w0lf.

Details
Exploit:
http://www.eviloctal.com/forum/read.php?tid=6913
曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题