There is a secondary injection of design defects in old versions of hdwiki

Source: Internet
Author: User

Secondary Injection for HDWiki-v5.1GBK-20121102 design defects


After logging on to the user, follow the steps shown in the image. When ignoring the list, the input items will be recorded in the wiki_pms table for the first time, and then submitted again, he will perform a check from the wiki_pms table. The SQL statements tracked in the background are: Check statement: select id, new, delstatus, og from wiki_pms where toid = 2 and delstatus! = 2 and drafts! = 1 and 'from 'not in ('dasd') or sleep (5) # ') insert statement: replace into wiki_blacklist (uid, blacklist) VALUES ('2 ', 'dasd \ ') or sleep (5) #') and submit the sleep function again to start execution.Solution:Filter the variables in each SQL statement.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.