Target: http://www.goodbaby.com/huaiyun/mamashow_single.php? Id = 13
Host IP: 202.108.251.195
Web Server: nginx/1.0.6
DB Server: MySQL
Current DB: cms
Data Bases: information_schema
Aclocal
Binlogs
Cms
Expert
Manage
Mysql
Phpcms
Subject
Test
Solution:
We still need to pay attention to security. We have to take actions without shouting slogans.
Good night.
Author: zeracker
A sensitive file on the children's main site can obtain any user information,
A file can query user information based on the user name,
Contains administrator information,
Expose the md5 password
Admin information queried
Object (stdClass) #1 (13 ){
["UserId"] =>
String (4) 1434"
["LoginName"] =>
String (5) "admin"
["NickName"] =>
String (5) "admin"
["Password"] =>
String (32) "17aa7f73186e5c6c89d71a70942f9265"
["Email"] =>
String (24) "master@goodbabygroup.com"
["MemberCardNo"] =>
String (0 )""
["LastLogin"] =>
String (19) "0000-00-00:00:00"
["Mobile"] =>
Md5 not decrypted
Then I tested the manager User and successfully logged on.
You have found an edit for yehan, and there is no background management after logon!
You have no choice but to find the next point!
Yes! After that, I sent a ticket to win the main site. Haha ~
Solution:
Delete this file if it is useless!
Author: Lightning kiddies