An injection vulnerability was unexpectedly a root privilege.
The results showed that all the servers were in a uniform password.
Let's take into consideration the fact that various dads want to register on your website.
Detailed description:
Http://www.goodbaby.com/tips/food/food.php? Id = 3701'
Run the following command: (Select * from VC_Food where id = 3701 select form vc_food where id = 3701): You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'select form vc_food where id = 3701 'at line 1
Proof of vulnerability:
Your data is a favorite of hackers for marketing and promotion of baby products.
There are a lot of tables and I will not read more about the test. It seems like plain text.
<
Read/etc/pass.
The passwords of dozens of servers are the same.
Permission allocation is not strictly controlled.
Solution:
Strengthen security system