http://www.nspcn.orghttp://www.tr4c3.comVersion:
BBSGood.Speed Version 4.0
漏洞文件:
UserInfo.asp
漏洞描述:
变量Blogurl未经过滤带入sql语句,导致Sql注入漏洞
代码举例:
行1729-1853.
case 14
if Request.QueryString("save")=1 then
if trim(Request.Form("blogurl"))<>"" then
Set rsdj = Server.CreateObject("ADODB.Recordset")
rsdj2="select id from LxTel_User where blogurl='"&trim(Request.Form("blogurl"))&"' "
rsdj.open rsdj2,conn,1,1
if not(rsdj.bof and rsdj.eof) then
rsdj.close
set rsdj=nothing
Response.Write "<script>alert('该二级域名地址,已经被人使用');history.back(-1);</script>"
Response.End
else
rsdj.close
set rsdj=nothing
end if
end if
...
利用方法:
本地架设测试如图1,2


测试官方如图3,4,5

