A weak password \ SQL injection vulnerability in a website in Digital China Getshell

Source: Internet
Author: User

A weak password \ SQL injection vulnerability in a website in Digital China Getshell

RT: Just stroll around to see if there are any vulnerabilities.

Vulnerability URL: http://dckf.digitalchina.com

First of all, I saw a great God used truncation to get the shell ....

Weak Password: Cheng Yan/123456789

Note: This is a weak password. The Administrator modified the policy last time. You cannot use a weak password to log on directly. You need to modify the information.

If I have modified it at the beginning and finished the test, I have changed it again .. The verification mechanism is poor ..

You can directly modify the email address and password. I will not attach the logon. Log on to


Under login: http://dckf.digitalchina.com/index.php/qa/qainput? Isetup-to-date = 1 & id = 374


The parameter id is injected ..
 


Test permission: root permission. Use sqlmap -- OS-shell to directly Getshell. (PS: Getshell was originally used, but failed. Haha ~~~~~~)
 



Is to use sqlmap to obtain a script for uploading arbitrary files... Getshell>.
 



Http://dckf.digitalchina.com/uploads/shangchuan.php ceshi123654


Troubleshoot the problem .... Try another test ..


 

 

Solution:

You know ..

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.