Discuz漏洞

不再关注网络安全

Discuz X1.5 X2.5 X3 用uc_key getshell

一、Discuz X1.5 X2.5 X3用uc_key来get webshell uc_key是UC客户端与服务端通信的通信密钥。因此使用uc_key来fetshell只能获取UCenter Client的webshell,即D...

Discuz交友插件漏洞附EXP

DZ交友插件漏洞jiaoyou.php?pid=1 有的注入需要登录,注入代码如下: ' or @' and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27...

discuz X2.5 爆物理地址路径漏洞!

/uc_server/control/admin/db.php /source/plugin/myrepeats/table/table_myrepeats.php /install/include/install_lang.php

Discuz7.X通杀0day(UCenter Home-2.0)

Dork : Powered by UCenter inurl:shop.php?ac=view Dork 2 : inurl:shop.php?ac=view&shopid= Vuln file : Shop.php =================================...