Multiple Injection and repair solutions for children's parenting Network

Source: Internet
Author: User

Brief description:
 
 
There are multiple SQL injections in children's care network, which are not strictly filtered and user data is leaked.
Detailed description:
 
 
Web Server: nginx/1.0.6
 
DB Server: MySQL
 
Current DB: ad
 
Http://a1.goodbaby.com/ad_alt_js.php? Zoneid = 678
 
Http://ad.goodbaby.com/ad_multibyid.php? Zoneid = 1
 
Http://ad.goodbaby.com/ad_alt_click.php? Z = 227 & B = 230% 5C
 
Http://ad.goodbaby.com/ad_alt_js.php? Zoneid = 1
 
Http://www.goodbaby.com/tips/goodbaby/serials/default.php? Topic_id = 5 & chapter_id = 14 & article_id = 6817
 
 

 
 
Proof of vulnerability:
 
 
You can see a lot of user information...
 
 
 
Solution:
 
 
The. php page is not strictly filtered, leading to the SQL injection vulnerability and filtering some characters. Determine the information submitted by the user. When the submitted parameters contain SQL Injection characters such as "exec, insert, select, delete, from, update, count, and user, turn to the error page.
 
Lazy author @ wooyun

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.